CVE-2025-55319 is a command injection vulnerability affecting agentic AI integrations used with Visual Studio Code. According to the provided content, the issue arises when an autonomous AI coding assistant processes untrusted external content—such as README files, code comments, or external documentation—and fails to adequately separate attacker-controlled instructions from trusted user intent. In this scenario, malicious natural-language content can be interpreted by the AI agent as legitimate operational instructions, leading the agent to perform unsafe actions inside the developer environment. Reported outcomes include unauthorized modification of files such as .vscode/settings.json, disabling of security-related settings, and arbitrary shell command execution. Publicly available material in the provided context does not identify a specific vulnerable function, code path, or precise affected version range.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept malicious VS Code extension packaged as a .vsix. Its purpose is to achieve code execution on a target workstation by abusing VS Code extension installation and automatic activation. The repository contains four files: a README explaining packaging and use, an OpenXML [Content_Types].xml manifest required for VSIX packaging, extension/package.json defining the extension metadata and activation behavior, and extension/extension.js containing the executable logic. The core exploit behavior is in extension/extension.js. When VS Code activates the extension, exports.activate() runs automatically because package.json sets activationEvents to ['*'], meaning activation occurs on startup/load without user interaction beyond installation. The script uses Node.js child_process.exec to launch PowerShell with -WindowStyle Hidden and -NoProfile, passing a base64-encoded payload via -e. The README describes replacing the placeholder with a UTF-16LE-encoded reverse shell that connects to an attacker-controlled listener (example: 10.10.15.158:4443). This yields an interactive reverse shell from the victim Windows host. This is not a detection script and not just documentation; it is a functioning exploit scaffold with a placeholder payload. It is best classified as OPERATIONAL because the execution mechanism is implemented and only requires the operator to insert a payload and package/install the extension. The attack vector is primarily local/file-based social engineering or delivery: the victim must install the malicious .vsix extension. Once installed, the extension provides stealthy command execution and reverse-shell access on Windows systems running VS Code with PowerShell available.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.