{"id":"CVE-2026-57102","details":"Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.","modified":"2026-07-22T04:18:43.440241Z","published":"2026-07-14T18:18:34.977Z","references":[{"type":"FIX","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/microsoft/vscode","events":[{"introduced":"c1d66b6e47c9da4c768ce7f216da14e7e4ac06ff"},{"fixed":"5264f2156cbcd7aea5fd004d29eaa10209155d66"}],"database_specific":{"cpe":"cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.128.1"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57102.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}