PT-2026-8356 · Unknown · Visual Studio Code Live Server

Published

2026-02-16

·

Updated

2026-02-25

·

CVE-2025-65717

CVSS v2.0

5.0

Medium

AV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Visual Studio Code Live Server version 5.7.9
Description An issue in Visual Studio Code Live Server allows attackers to exfiltrate files through user interaction with a specially crafted HTML page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Open Redirect

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-02194
CVE-2025-65717

Affected Products

Visual Studio Code Live Server