Researchers disclosed multiple high-severity vulnerabilities in widely used Visual Studio Code extensions, including Live Server, Markdown Preview Enhanced, Code Runner, and Microsoft Live Preview, exposing developers to local file theft, cross-site scripting, data exfiltration, and remote code execution. Three issues were assigned identifiers CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717, with separate disclosures highlighting flaws in Markdown Preview Enhanced and Live Server.
The most severe issue, CVE-2025-65717 in Live Server, could allow a remote unauthenticated attacker to exfiltrate files from a developer workstation through localhost access if the victim opens a malicious website. Security guidance accompanying the disclosures urged organizations to update affected VS Code extensions to fixed versions, restrict installed extensions to those that are necessary, and prefer trusted publishers to reduce developer workstation exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an advisory summarizing Ox Security's findings on critical vulnerabilities in Visual Studio Code extensions. The advisory recommended updating affected extensions to fixed versions and limiting installed extensions to only those necessary and from trusted sources.
Ox Security researchers identified serious vulnerabilities in several popular Visual Studio Code extensions, including Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. The issues included local file theft, cross-site scripting, data exfiltration, and remote code execution, with CVEs assigned to three of the flaws.
A vulnerability tracked as CVE-2025-65717 was disclosed in the Live Server VS Code extension. CSIRT.SK described it as the most severe issue, allowing a remote unauthenticated attacker to exfiltrate files from a developer machine via localhost access when the victim opens a malicious website.
A vulnerability tracked as CVE-2025-65716 was disclosed in the Markdown Preview Enhanced VS Code extension. The flaw was part of Ox Security's reporting on critical extension security issues affecting developers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceox.security
Open sourceox.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.