A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to convince a target to open a specially crafted file in Visual Studio Code with the Python extension installed.
The update address the vulnerability by modifying the way Visual Studio Code Python extension enforces user settings.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1171. A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to convince a target to open a specially crafted file in Visual Studio Code with the Python extension installed. The update address the vulnerability by modifying the way Visual Studio Code Python extension enforces user settings.
Title Visual Studio Code Python Extension Remote Code Execution Vulnerability
First Time appeared Microsoft visual Studio Code
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft visual Studio Code
References

Tue, 08 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft python
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:python:*:* cpe:2.3:a:microsoft:python:*:*:*:*:*:visual_studio_code:*:*
Vendors & Products Microsoft visual Studio Code
Microsoft python

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-19T16:33:15.177Z

Reserved: 2019-11-04T00:00:00.000Z

Link: CVE-2020-1192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-21T23:15:18.837

Modified: 2026-08-19T17:17:34.207

Link: CVE-2020-1192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses