Cybersecuritynews
Critical Vulnerabilities in VS Code Extensions Expose Developers to Attacks
First seen 18 Feb 2026, 09:15 UTC
•



+11
•83% similarity
•26.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Multiple vulnerabilities affecting popular Visual Studio Code (VS Code) extensions, including the Live Preview extension, have been discovered, exposing developers to risks such as local file exfiltration and remote code execution. The flaws, identified by researchers from OX Security, impact extensions with over 128 million downloads. Key vulnerabilities include CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717, all published on February 16, 2026.
ThreatCluster AI
Timeline
2026-02-16
CVE-2025-65715 published
2026-02-16
CVE-2025-65716 published
2026-02-16
CVE-2025-65717 published
2026-02-18
Microsoft Live Preview vulnerability reported