Flaws in popular VSCode extensions expose developers to attacks
Popular Visual Studio Code (VSCode) extensions that have been downloaded over 128 million times combined have vulnerabilities with high to critical severity ratings that might be used to remotely execute code and steal local files.
The security flaws affect Microsoft Live Preview (no identification allocated), Code Runner (CVE-2025-65715), and Markdown Preview Enhanced (CVE-2025-65716, CVE-2025-65717).
Ox Security's application security researchers found the vulnerabilities and have been working to make them public since June 2025. But according to the researchers, no maintenance replied.
The capabilities of Microsoft's integrated development environment (IDE) can be increased with the help of VSCode extensions. They can include themes, debugging tools, language support, and addi...




