Security researchers at Ox Security reported multiple high-to-critical vulnerabilities in widely used Visual Studio Code extensions—collectively exceeding 128 million downloads—that could enable local file exfiltration and code execution in developer environments. The issues highlighted include Live Server (CVE-2025-65717), Code Runner (CVE-2025-65715, referenced in reporting but not included as a CVE entry here), Markdown Preview Enhanced (CVE-2025-65716), and Microsoft Live Preview (no CVE cited in the reporting). Ox Security stated it attempted disclosure starting in June 2025 but did not receive responses from maintainers, warning that exploitation could support lateral movement, data theft, and system takeover in corporate networks where developer workstations are a pivot point.
The CVE records included in this set describe two of the extension flaws in more detail: CVE-2025-65717 (Live Server v5.7.9) allows attackers to exfiltrate files when a user interacts with a crafted HTML page, and CVE-2025-65716 (Markdown Preview Enhanced v0.8.18) can lead to arbitrary code execution via a crafted .md file (user interaction required). Other items in the feed are unrelated, covering a broad mix of independent vulnerabilities (e.g., Tenable Security Center command injection, LightLLM unsafe deserialization RCE, libvpx heap overflow affecting Firefox/Thunderbird, and multiple router/IoT hard-coded credential and command-injection issues) and should not be treated as part of the VSCode-extension disclosure story.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On Feb. 18, 2026, CVE-2025-65791 was updated with technical details describing a command injection flaw in ZoneMinder v1.36.34's web/views/image.php, where unsanitized input reaches exec(). The record added CVSS scoring, CWE classification, and a public reference, indicating unauthenticated remote exploitation with high impact.
OX Security disclosed multiple high-to-critical vulnerabilities in Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview, warning they could enable file theft, remote code execution, lateral movement, and full system compromise. The report said the issues also affect VSCode-compatible IDEs such as Cursor and Windsurf and impact extensions with more than 128 million combined downloads.
On Feb. 17, 2026, the CVE records for CVE-2025-65716 and CVE-2025-65717 were updated with CVSS scoring, CWE classifications, and references to project repositories and third-party research. The updates characterized the flaws as high-severity issues affecting Markdown Preview Enhanced and Live Server.
MITRE received CVE records for two Visual Studio Code extension vulnerabilities: CVE-2025-65716 in Markdown Preview Enhanced and CVE-2025-65717 in Live Server. The issues involve arbitrary code execution via a crafted Markdown file and file exfiltration via a crafted HTML page, respectively.
OX Security said it started responsible disclosure efforts in June 2025 for multiple vulnerabilities affecting popular Visual Studio Code extensions, but reported receiving no response from maintainers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.