CVE-2025-65715Disclosure(formulahendry / coderunner)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch formulahendry coderunner systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coderunner

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 19 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 11 classified signals
  • General: 5 classified signals
  • Peaked 6d ago at 7 mentions (2026-02-18); latest day: 1
  • 19 total mentions across 9 days

Affected systems

Products
coderunner

Deep dive

Activity timeline19 mentions / 9d
02457Mentions · 2026-02-16: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 7Mentions · 2026-02-19: 2Mentions · 2026-02-20: 2Mentions · 2026-02-24: 1Mentions · 2026-02-26: 2Mentions · 2026-03-16: 1Mentions · 2026-05-03: 1Active Exploitation · 2026-02-18: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 5Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-26: 1Technical Details · 2026-03-16: 1Technical Details · 2026-05-03: 102-1602-1702-1802-1902-2002-2402-2603-1605-03
Signal classification3 categories
Disclosure
1157.9%
General
526.3%
Patch
315.8%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-161
Disclosure1
2026-02-172
Disclosure1General1
2026-02-187
Disclosure4General2Patch1
2026-02-192
Disclosure1Patch1
2026-02-202
Disclosure2
2026-02-241
Disclosure1
2026-02-262
Disclosure1General1
2026-03-161
Patch1
2026-05-031
General1
Full discourse19 posts
  • kokumօtօ@__kokumoto
    Disclosure

    VSCodeの人気拡張機能複数に脆弱性。Ox Security社報告。Code Runner (CVE-2025-65715)、Markdown Preview Enhanced (CVE-2025-65716)…Markdown Preview Enhanced (CVE-2025-65717)、Microsoft Live Preview(CVE未採番)。 https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    The text announces new vulnerabilities in several popular VSCode extensions (CVE-2025-65715, -65716, -65717) reported by Ox Security, without providing technical details, PoC, or remediation guidance.

    230751.7K
    7.1K followersView on X
  • Sofyan Setiawan@sofyansetiawann
    Disclosure

    3 ekstensi VSCode yang ada vulnerability: - Live Server (pencurian local file) - Markdown Preview Enhanced (open .md, eksekusi js di dalamnya) - Code Runner (paste config) References: https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/ http://ox.security/blog/cve-2025-65715-code-runner-vscode-rce/ http://ox.security/blog/cve-2025-65716-markdown-preview-enhanced-vscode-vulnerability/

    Post summary

    Three VSCode extensions—Live Server, Markdown Preview Enhanced, and Code Runner—have reported vulnerabilities ranging from local file theft to JavaScript execution and RCE, with links to detailed security blog posts.

    00033234
    3.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical VS Code Extension Flaws Put 128M+ Installs at Risk of File Theft and Remote Code Execution High-to-critical vulnerabilities in popular VS Code extensions—Live Server (CVE-2025-65715), Code Runner (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview—can enable local file exfiltration, XSS via crafted Markdown, and RCE via malicious configs, impacting VS Code-compatible IDEs like Cursor and Windsurf. Patch/remove affected extensions and treat untrusted workspaces/configs/files as hostile to prevent lateral movement and secret theft (API keys, configs). 🎯 Target: Global/Developers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/critical-vscode-extension-vulnerabilities-could-lead-to-code-execution-and-data-theft

    Post summary

    The post announces critical vulnerabilities in several VS Code extensions, details the attack vectors, and urges users to patch or remove the affected extensions to mitigate file theft and remote code execution risks.

    00011119
    174 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    VS Code の 4 件のエクステンションに深刻な脆弱性:累計インストール数は 1億2,500万回を超える https://iototsecnews.jp/2026/02/18/critical-flaws-found-in-four-vs-code-extensions-with-over-125-million-installs/ 公表された問題の背景にあるのは、localhost 上のサービスやローカル・ファイルへ過度にアクセスを許す、VS Code エクステンション設計です。CVE-2025-65717/CVE-2025-65716 では、悪意の Web サイトや .md ファイルを通じて JavaScript が実行され、ローカル開発サーバやポートが探索され、機密情報が外部に送信されます。また、CVE-2025-65715 では settings.json の改変により任意コード実行が成立します。拡張機能の権限分離や入力検証が不十分であった点が、ラテラル・ムーブメントの足掛かりとなっています。ご利用のチームは、ご注意ください。よろしければ、VS Code での検索結果も、ご参照ください。 #CodeRunner #CVE202565715 #CVE202565716 #CVE202565717 #Extension #LiveServer #MarkdownPreviewEnhanced #Microsoft #VSCode #Vulnerability

    Post summary

    Four VS Code extensions contain critical flaws that enable arbitrary code execution via malicious JavaScript or tampered settings.json, potentially exposing local development server information to external recipients.

    01000164
    485 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    VS Codeの主要な拡張機能4件で危険性のある脆弱性-最大1.2億に影響(CVE-2025-65717,CVE-2025-65715,CVE-2025-65716) https://rocket-boys.co.jp/security-measures-lab/four-major-vscode-extensions-hit-by-critical-flaws-affecting-up-to-120-million-installs-cve-2025-65715-cve-2025-65716-cve-2025-65717/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but does not provide PoC, exploit, or patch details.

    00010158
    319 followersView on X
  • 𓊈𒆜🅲🆁🅸🆂🆃🅸🅰🅽 𒆜𓊉@Cris7ianJCC
    Disclosure

    CVE-2025-65715 (CVSS 7.8): En Code Runner, permite la ejecución de código arbitrario al persuadir al usuario para que modifique el archivo "settings.json".

    Post summary

    The text announces CVE‑2025‑65715, an arbitrary code execution vulnerability in Code Runner that requires a user to edit "settings.json" to trigger the exploit.

    1000054
    662 followersView on X
  • Autumn Good@autumn_good_35
    General

    『Three were assigned CVEs – CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717 – totaling over 120 million downloads and posing a significant threat to developers worldwide.』 Four Vulnerabilities Expose a Massive Security Blind Spot in IDE Extensions https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The post lists three CVEs and notes their widespread downloads, but offers no technical details, PoC, exploit, or patch information.

    00001450
    6.7K followersView on X
  • Peace Mathew | Developer@zyron_tech10
    General

    Campvio lost $100B due to the use of VS Code in development. The risk isn't the IDE, but extensions like "Code Runner" (CVE-2025-65715), which allowed RCE in early 2026. With millions of installs, it’s a massive supply chain risk. Be careful which extensions you install!

    Post summary

    The tweet announces a security issue (CVE‑2025‑65715) in a VS Code extension that permits remote code execution, highlighting a supply‑chain risk but providing no PoC, exploit code, patch, or evidence of active exploitation.

    00000909
    1.8K followersView on X
  • Wisr AI@Wisr_AI
    Patch

    Most teams monitor code. Few monitor editor settings. CVE-2025-65715: VS Code Code Runner shows settings.json/executorMap can enable RCE + persistence. Takeaway: lock settings, restrict workspace overrides, treat extensions as privileged. Watching settings.json like code? #AI https://t.co/1rLmcRKaCh

    Post summary

    The tweet alerts on CVE‑2025‑65715 in VS Code Code Runner, highlighting an RCE vector through executorMap in settings.json and recommends locking settings and restricting workspace overrides as mitigation.

    00000129
    118 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2025-65716 ❗ CVE-2025-65715 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-6/ https://t.co/Lu1r6yBSRd

    Post summary

    The tweet lists two Microsoft CVEs and directs readers to a link for more information, but offers no additional details or context.

    00000154
    6.6K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 128M VS Code Extension Installs Exposed: Critical CVEs Enable RCE & File Exfiltration From Developer Machines OX Security disclosed three critical flaws (CVE-2025-65715/65716/65717) across widely used VS Code extensions (Live Server, Code Runner, Markdown Preview Enhanced) that can enable remote code execution, JavaScript-driven local probing, and remote file exfiltration via localhost workflows—turning a developer workstation into a high-value supply-chain pivot. The report also notes a one-click XSS-to-IDE file exfiltration issue in Microsoft Live Preview (patched in v0.4.16+) and urges immediate extension auditing and hardening of localhost/HTML handling. 🎯 Target: Global/Software Development (Developer Endpoints) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/popular-vs-code-extensions-vulnerability/

    Post summary

    OX Security disclosed three critical CVEs (CVE-2025-65715/65716/65717) that allow RCE and file exfiltration in popular VS Code extensions, with a patch available for Live Preview and a call for immediate hardening of localhost/HTML handling.

    0000068
    174 followersView on X
  • Grok@grok
    Disclosure

    1. **How it works**: Vulnerabilities exploit localhost servers or crafted files. E.g., Live Server (CVE-2025-65717) lets malicious sites steal files from its dev server; Markdown Preview Enhanced (CVE-2025-65716) runs arbitrary JS via .md files; Code Runner (CVE-2025-65715) enables code exec via settings tweaks; Microsoft Live Preview allowed file access (now fixed). 2. **Why it matters**: These affect 125M+ installs, risking data theft, code execution, and lateral attacks from a single flaw, threatening devs and orgs. 3. **Potential impacts on existing plugins**: Could enable chaining attacks to compromise other extensions, steal credentials, or spread malware across VS Code ecosystem if not mitigated via updates/uninstalls.

    Post summary

    The post announces newly discovered vulnerabilities in VS Code extensions that allow local file access, arbitrary code execution, and potential lateral attacks, emphasizing the need for updates or removal to mitigate risk.

    00000325
    8.0M followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 125M+ VS Code Installs at Risk: 4 Popular Extensions Enable File Exfiltration & Remote Code Execution OX Security disclosed high/critical flaws across Live Server (CVE-2025-65717), Code Runner (CVE-2025-65715), and Markdown Preview Enhanced (CVE-2025-65716), plus an issue in Microsoft Live Preview, enabling attacker-triggered local file exfiltration and in some cases RCE via malicious content/preview/localhost abuse. This matters because IDE extensions run in trusted developer environments—turning a single booby-trapped project or link into a high-impact entry point for source-code theft and workstation compromise. 🎯 Target: Global/Developers & Software Teams #️⃣ Category: #Vulnerability #CyberIntel #BlueTeam 🔗 URL: https://securityaffairs.com/188185/security/vs-code-extensions-with-125m-installs-expose-users-to-cyberattacks.html

    Post summary

    OX Security disclosed critical CVEs affecting popular VS Code extensions, highlighting potential file exfiltration and remote code execution risks, but no PoC, patch, or evidence of active exploitation was provided.

    00000178
    174 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Disclosure

    The security issues impact Code Runner (CVE-2025-65715), Markdown Preview Enhanced (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview (no identifier assigned). https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    The article announces newly identified vulnerabilities affecting popular VSCode extensions, listing CVE identifiers but offering no exploit code, patch information, or evidence of active exploitation.

    00000178
    911 followersView on X
  • Machina Record@MachinaRecord
    General

    【リンク集:2月17日〜18日のセキュリティ関連ニュース/記事】 <脆弱性> ・TomcatのOpenID Connect認証システムにおけるJWT認証バイパスの脆弱性 https://insinuator.net/2026/02/jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/ ・Dellのゼロデイ脆弱性、2024年半ばから中国系ハッカーグループが悪用(CVE-2026-22769) https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/ ・米CISA、KEVカタログに4件の脆弱性を追加(CVE-2026-2441、CVE-2008-0015他) https://www.cisa.gov/known-exploited-vulnerabilities-catalog ・人気のVSCode拡張機能に複数の脆弱性、開発者を攻撃リスクにさらす(CVE-2025-65715、CVE-2025-65716他) https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/ <マルウェア・その他脅威> ・ハッカーがScreenConnectを悪用、米社会保障局に扮した偽メールでPC乗っ取る https://hackread.com/hackers-screenconnect-hijack-pcs-fake-social-security-emails/ ・Intellexa製スパイウェア「Predator」でアンゴラ人ジャーナリストのiPhoneがハッキングされるhttps://techcrunch.com/2026/02/17/intellexas-predator-spyware-used-to-hack-iphone-of-journalist-in-angola-research-says/ ・複数メーカーのタブレットにファームウェアレベルのAndroidバックドアが見つかる https://www.helpnetsecurity.com/2026/02/17/firmware-level-android-backdoor-keenadu-tablets/ ・SmartLoader攻撃、トロイの木馬化されたOura MCPサーバーでStealCインフォスティーラーを展開 https://thehackernews.com/2026/02/smartloader-attack-uses-trojanized-oura.html <データ侵害/サイバー犯罪> ・カナダグース、流出した顧客取引データと最近の社内システム侵害は無関係と発表 https://therecord.media/canada-goose-says-leaked-customer-data-was-not-from-company <AI関連> ・欧州議会、各議員のデバイスに搭載されたAIツールを無効化 セキュリティリスクを考慮 https://techcrunch.com/2026/02/17/european-parliament-blocks-ai-on-lawmakers-devices-citing-security-risks/ ・「AIで要約」ボタンに潜むプロンプトがレコメンド機能を操作 マイクロソフトが発見 https://thehackernews.com/2026/02/microsoft-finds-summarize-with-ai.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・アイルランドでもXの捜査を開始 Grokが作成した性的画像に関して https://www.bleepingcomputer.com/news/security/ireland-now-also-investigating-x-over-grok-made-sexual-images/ ・Phobosランサムウェアのアフィリエイトがポーランドで逮捕される https://www.helpnetsecurity.com/2026/02/17/phobos-ransomware-affiliate-arrested-in-poland/ ・スペイン当局、NordVPNとProtonVPNにラ・リーガ海賊版サイトのブロックを命令https://www.bleepingcomputer.com/news/legal/spain-orders-nordvpn-protonvpn-to-block-laliga-piracy-sites/ <プライバシー> ・米法律事務所、プライバシー侵害でレノボを集団訴訟 中国へデータを「大量移転」と指摘 https://www.theregister.com/2026/02/17/lenovo_privacy_lawsuit/ ・アマチュアプログラマー、手違いで世界中のロボット掃除機にアクセス https://www.malwarebytes.com/blog/news/2026/02/hobby-coder-accidentally-creates-vacuum-robot-army ・マイカーが強力なスパイツールに イスラエル企業が監視技術をリード https://www.haaretz.com/israel-news/security-aviation/2026-02-16/ty-article-magazine/.premium/your-car-is-spying-on-you-and-israeli-firms-are-leading-the-surveillance-race/0000019c-6651-d2f0-a19c-7fdd81920000 ・ケニア当局がセレブライトを使用 反体制派の携帯電話にアクセス https://therecord.media/spyware-kenya-cellebrite-activist <リサーチ/攻撃手法/TTP> ・2025年にICS/OTを攻撃した脅威グループ3選 Dragosが紹介 https://www.securityweek.com/3-threat-groups-started-targeting-ics-ot-in-2025-dragos/ ・フィッシング攻撃で利用された偽のインシデントレポート https://isc.sans.edu/diary/32722 ・CopilotとGrokがマルウェアのC2プロキシとして悪用される恐れ 研究で明らかに https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html <その他> ・Microsoft Teamsで障害発生 米国とヨーロッパのユーザーが影響受ける https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outage-affects-users-in-united-states-europe/ ・Notepad++、アップデートのセキュリティを「ダブルロック」機構で強化 https://www.bleepingcomputer.com/news/security/notepad-plus-plus-boosts-update-security-with-double-lock-mechanism/

    Post summary

    The text lists several recent security news items, including CVE disclosures and an active exploitation of a Dell zero‑day, but provides only high‑level details and no code or patch information.

    00000227
    1.2K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Three high to critical vulns in VSCode. Info, incl. fixes, at SecAlerts: CVE-2025-65715: https://secalerts.co/vulnerability/CVE-2025-65715 CVE-2025-65716, CVSS 8.8: https://secalerts.co/vulnerability/CVE-2025-65716 CVE-2025-65717, CVSS 9.1: https://secalerts.co/vulnerability/CVE-2025-65717 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #vscode https://t.co/k7p5Dk2kFG

    Post summary

    Three critical VSCode vulnerabilities (CVE‑2025‑65715, CVE‑2025‑65716, CVE‑2025‑65717) are disclosed with CVSS scores and links to available fixes.

    00000172
    796 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    I disclosed these vulnerabilities and got issued 3 out of 4 CVEs CVE-2025-65715: Code Runner (37M+) CVE-2025-65716: Markdown Preview Enhanced (8.5M+) CVE-2025-65717: Live Server (72M+) No CVE (but fixed): Live Preview by Microsoft (11M+) https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The author announces the disclosure of three CVEs impacting popular IDE extensions, listing the CVE identifiers and affected extensions, but provides no PoC, technical details, or evidence of active exploitation.

    00000151
    79 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    General

    We Found 4 Vulnerabilities in IDE Extensions With Over 120M(!) Downloads 3 of them were issued a CVE & the only one without a CVE is the only one that was fixed.. WHAT? 😶 CVE-2025-65715: Code Runner CVE-2025-65716: Markdown CVE-2025-65717: Live Server https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The post announces four vulnerabilities in IDE extensions, lists their CVE numbers, but provides no technical, exploit, or mitigation details.

    00000104
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-65715 Code Execution Vulnerability in Visual Studio Code Extensions Code Runner v0.12.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-65715

    Post summary

    The text announces CVE‑2025‑65715, a code execution vulnerability in the Code Runner extension v0.12.2 for Visual Studio Code, without mentioning any PoC, exploit, or patch.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appformulahendrycoderunner-visual_studio_code-

Explore more