CVE-2025-65716Disclosure(shd101wyy / markdown_preview_enhanced)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch shd101wyy markdown_preview_enhanced systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • markdown_preview_enhanced

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • General: 5 classified signals
  • Peaked 4d ago at 7 mentions (2026-02-18); latest day: 2
  • 16 total mentions across 6 days

Affected systems

Vendors
Products
markdown_preview_enhanced

Deep dive

Activity timeline16 mentions / 6d
02457Mentions · 2026-02-17: 2Mentions · 2026-02-18: 7Mentions · 2026-02-19: 3Mentions · 2026-02-20: 1Mentions · 2026-02-24: 1Mentions · 2026-02-26: 2PoC Mentioned / Linked · 2026-02-18: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-18: 5Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-26: 102-1702-1802-1902-2002-2402-26
Signal classification3 categories
Disclosure
956.3%
General
531.3%
Patch
212.5%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-172
Disclosure2
2026-02-187
Disclosure5General1Patch1
2026-02-193
General2Patch1
2026-02-201
Disclosure1
2026-02-241
General1
2026-02-262
Disclosure1General1
Full discourse16 posts
  • kokumօtօ@__kokumoto
    Disclosure

    VSCodeの人気拡張機能複数に脆弱性。Ox Security社報告。Code Runner (CVE-2025-65715)、Markdown Preview Enhanced (CVE-2025-65716)…Markdown Preview Enhanced (CVE-2025-65717)、Microsoft Live Preview(CVE未採番)。 https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    Multiple popular VSCode extensions have been identified as vulnerable, with CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717 disclosed by Ox Security.

    230751.7K
    7.1K followersView on X
  • Sofyan Setiawan@sofyansetiawann
    Disclosure

    3 ekstensi VSCode yang ada vulnerability: - Live Server (pencurian local file) - Markdown Preview Enhanced (open .md, eksekusi js di dalamnya) - Code Runner (paste config) References: https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/ http://ox.security/blog/cve-2025-65715-code-runner-vscode-rce/ http://ox.security/blog/cve-2025-65716-markdown-preview-enhanced-vscode-vulnerability/

    Post summary

    The post announces new CVE vulnerabilities in three VSCode extensions, highlighting potential local file theft, JavaScript execution within markdown files, and configuration issues.

    00033234
    3.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical VS Code Extension Flaws Put 128M+ Installs at Risk of File Theft and Remote Code Execution High-to-critical vulnerabilities in popular VS Code extensions—Live Server (CVE-2025-65715), Code Runner (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview—can enable local file exfiltration, XSS via crafted Markdown, and RCE via malicious configs, impacting VS Code-compatible IDEs like Cursor and Windsurf. Patch/remove affected extensions and treat untrusted workspaces/configs/files as hostile to prevent lateral movement and secret theft (API keys, configs). 🎯 Target: Global/Developers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/critical-vscode-extension-vulnerabilities-could-lead-to-code-execution-and-data-theft

    Post summary

    Critical VS Code extension vulnerabilities (CVE-2025-65715, 65716, 65717) enable file theft, XSS, and RCE; immediate patch or removal of the affected extensions is advised to mitigate the risk.

    00011119
    174 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    VS Code の 4 件のエクステンションに深刻な脆弱性:累計インストール数は 1億2,500万回を超える https://iototsecnews.jp/2026/02/18/critical-flaws-found-in-four-vs-code-extensions-with-over-125-million-installs/ 公表された問題の背景にあるのは、localhost 上のサービスやローカル・ファイルへ過度にアクセスを許す、VS Code エクステンション設計です。CVE-2025-65717/CVE-2025-65716 では、悪意の Web サイトや .md ファイルを通じて JavaScript が実行され、ローカル開発サーバやポートが探索され、機密情報が外部に送信されます。また、CVE-2025-65715 では settings.json の改変により任意コード実行が成立します。拡張機能の権限分離や入力検証が不十分であった点が、ラテラル・ムーブメントの足掛かりとなっています。ご利用のチームは、ご注意ください。よろしければ、VS Code での検索結果も、ご参照ください。 #CodeRunner #CVE202565715 #CVE202565716 #CVE202565717 #Extension #LiveServer #MarkdownPreviewEnhanced #Microsoft #VSCode #Vulnerability

    Post summary

    Four VS Code extensions contain critical flaws that enable remote code execution through malicious JavaScript or settings.json tampering, potentially exposing local development servers and sensitive data.

    01000164
    485 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    VS Codeの主要な拡張機能4件で危険性のある脆弱性-最大1.2億に影響(CVE-2025-65717,CVE-2025-65715,CVE-2025-65716) https://rocket-boys.co.jp/security-measures-lab/four-major-vscode-extensions-hit-by-critical-flaws-affecting-up-to-120-million-installs-cve-2025-65715-cve-2025-65716-cve-2025-65717/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but provides no further technical or mitigation details.

    00010158
    319 followersView on X
  • たまき@tamaki2
    Disclosure

    こらどういう脆弱性かと思ったら、悪意あるmdを読み込んだ時に任意のコード実行されるっていうやつか。 https://www.ox.security/blog/cve-2025-65716-markdown-preview-enhanced-vscode-vulnerability/

    Post summary

    The text references CVE‑2025‑65716, noting that malicious Markdown files can trigger arbitrary code execution in the VSCode Markdown Preview Enhanced extension; no exploit code, patch, or active exploitation is mentioned.

    00010344
    726 followersView on X
  • 𓊈𒆜🅲🆁🅸🆂🆃🅸🅰🅽 𒆜𓊉@Cris7ianJCC
    Disclosure

    CVE-2025-65716 (CVSS 8.8): En Markdown Preview Enhanced, posibilita la ejecución de código JavaScript arbitrario mediante la carga de archivos markdown manipulados.

    Post summary

    The post announces CVE-2025-65716, noting a high CVSS score of 8.8 and that the flaw allows arbitrary JavaScript execution via manipulated markdown files in Markdown Preview Enhanced.

    10000122
    662 followersView on X
  • Autumn Good@autumn_good_35
    General

    『Three were assigned CVEs – CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717 – totaling over 120 million downloads and posing a significant threat to developers worldwide.』 Four Vulnerabilities Expose a Massive Security Blind Spot in IDE Extensions https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The post highlights three newly assigned CVEs with high download counts, indicating a serious threat to developers, but lacks detailed technical information, PoCs, exploits, or patch guidance.

    00001450
    6.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2025-65716 ❗ CVE-2025-65715 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-6/ https://t.co/Lu1r6yBSRd

    Post summary

    The tweet lists two Microsoft CVEs and directs readers to a link for more information, but it does not provide any technical details, exploitation evidence, or mitigation guidance.

    00000154
    6.6K followersView on X
  • moatom@moatom
    General

    https://www.ox.security/blog/cve-2025-65716-markdown-preview-enhanced-vscode-vulnerability/ 😇

    Post summary

    The provided text is merely a URL reference with no explicit details about the CVE, its exploitation, or mitigation.

    00000109
    192 followersView on X
  • Grok@grok
    General

    1. **How it works**: Vulnerabilities exploit localhost servers or crafted files. E.g., Live Server (CVE-2025-65717) lets malicious sites steal files from its dev server; Markdown Preview Enhanced (CVE-2025-65716) runs arbitrary JS via .md files; Code Runner (CVE-2025-65715) enables code exec via settings tweaks; Microsoft Live Preview allowed file access (now fixed). 2. **Why it matters**: These affect 125M+ installs, risking data theft, code execution, and lateral attacks from a single flaw, threatening devs and orgs. 3. **Potential impacts on existing plugins**: Could enable chaining attacks to compromise other extensions, steal credentials, or spread malware across VS Code ecosystem if not mitigated via updates/uninstalls.

    Post summary

    The passage describes four CVEs affecting VS Code extensions that allow malicious sites or crafted files to steal files, execute arbitrary JavaScript, and run code via settings tweaks, highlighting significant risks to users.

    00000325
    8.0M followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 125M+ VS Code Installs at Risk: 4 Popular Extensions Enable File Exfiltration & Remote Code Execution OX Security disclosed high/critical flaws across Live Server (CVE-2025-65717), Code Runner (CVE-2025-65715), and Markdown Preview Enhanced (CVE-2025-65716), plus an issue in Microsoft Live Preview, enabling attacker-triggered local file exfiltration and in some cases RCE via malicious content/preview/localhost abuse. This matters because IDE extensions run in trusted developer environments—turning a single booby-trapped project or link into a high-impact entry point for source-code theft and workstation compromise. 🎯 Target: Global/Developers & Software Teams #️⃣ Category: #Vulnerability #CyberIntel #BlueTeam 🔗 URL: https://securityaffairs.com/188185/security/vs-code-extensions-with-125m-installs-expose-users-to-cyberattacks.html

    Post summary

    OX Security has disclosed critical flaws in four popular VS Code extensions that allow local file exfiltration and remote code execution, posing a significant risk to developers and teams.

    00000178
    174 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Disclosure

    The security issues impact Code Runner (CVE-2025-65715), Markdown Preview Enhanced (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview (no identifier assigned). https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    The article reports the disclosure of three new CVEs affecting VS Code extensions, providing identifiers and affected components but no exploit or mitigation details.

    00000178
    911 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Three high to critical vulns in VSCode. Info, incl. fixes, at SecAlerts: CVE-2025-65715: https://secalerts.co/vulnerability/CVE-2025-65715 CVE-2025-65716, CVSS 8.8: https://secalerts.co/vulnerability/CVE-2025-65716 CVE-2025-65717, CVSS 9.1: https://secalerts.co/vulnerability/CVE-2025-65717 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #vscode https://t.co/k7p5Dk2kFG

    Post summary

    The tweet announces three high‑severity VSCode vulnerabilities and directs readers to SecAlerts links that include fixes.

    00000172
    796 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    I disclosed these vulnerabilities and got issued 3 out of 4 CVEs CVE-2025-65715: Code Runner (37M+) CVE-2025-65716: Markdown Preview Enhanced (8.5M+) CVE-2025-65717: Live Server (72M+) No CVE (but fixed): Live Preview by Microsoft (11M+) https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The user disclosed three CVE‑numbered vulnerabilities affecting popular VS Code extensions and provided a link to a blog post, but no technical details, PoC, or exploit code are mentioned.

    00000151
    79 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    We Found 4 Vulnerabilities in IDE Extensions With Over 120M(!) Downloads 3 of them were issued a CVE & the only one without a CVE is the only one that was fixed.. WHAT? 😶 CVE-2025-65715: Code Runner CVE-2025-65716: Markdown CVE-2025-65717: Live Server https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The post announces four vulnerabilities in popular IDE extensions, lists their CVE identifiers, notes that one was fixed, but provides no technical, exploit, or mitigation details.

    00000104
    79 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshd101wyymarkdown_preview_enhanced-visual_studio_code-

Explore more