VS Code - Remote Code Execution Vulnerability
A remote code execution vulnerability exists in VS Code 1.109.0 and earlier versions where workspace trust was not always demanded to start MCP servers.
Patches
The fix is available starting with VS Code 1.109.1. The fix mitigates this attack by performing explicitly demanding trust before starting MCP servers.
Workarounds
Do not use interact with Copilot on untrusted workspaces in VS Code versions prior to 1.109.1.
References
VS Code - Remote Code Execution Vulnerability
A remote code execution vulnerability exists in VS Code 1.109.0 and earlier versions where workspace trust was not always demanded to start MCP servers.
Patches
The fix is available starting with VS Code 1.109.1. The fix mitigates this attack by performing explicitly demanding trust before starting MCP servers.
Workarounds
Do not use interact with Copilot on untrusted workspaces in VS Code versions prior to 1.109.1.
References