PT-2026-8354 · Microsoft+1 · Visual Studio Code+1

Published

2026-02-16

·

Updated

2026-03-31

·

CVE-2025-65715

CVSS v3.1

7.8

High

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Code Runner versions prior to 0.12.2
Description A flaw exists in the code-runner.executorMap setting of the Code Runner extension for Visual Studio Code. This allows for the execution of arbitrary code when a specially crafted workspace is opened. The executorMap setting is vulnerable to manipulation, enabling attackers to execute unintended code. The vulnerable parameter is code-runner.executorMap.
Recommendations Update to a version of Code Runner greater than or equal to 0.12.2.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-65715

Affected Products

Codeql Runner
Visual Studio Code