CVE-2025-65717Disclosure(ritwickdey / live_server)

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ritwickdey live_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-200CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • live_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 13 signals
  • Disclosure: 18 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 8 mentions (2026-02-18); latest day: 1
  • 22 total mentions across 7 days

Affected systems

Vendors
Products
live_server

Deep dive

Activity timeline22 mentions / 7d
02468Mentions · 2026-02-16: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 8Mentions · 2026-02-19: 7Mentions · 2026-02-20: 2Mentions · 2026-02-24: 1Mentions · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-18: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-18: 2Patch / Workaround · 2026-02-19: 4Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-18: 4Technical Details · 2026-02-19: 6Technical Details · 2026-02-20: 2Technical Details · 2026-02-26: 102-1602-1702-1802-1902-2002-2402-26
Signal classification3 categories
Disclosure
1881.8%
General
29.1%
Patch
29.1%
Referenced assets17 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-161
Disclosure1
2026-02-172
Disclosure2
2026-02-188
Disclosure6General1Patch1
2026-02-197
Disclosure5General1Patch1
2026-02-202
Disclosure2
2026-02-241
Disclosure1
2026-02-261
Disclosure1
Full discourse20 posts
  • しまぶーのIT大学@shimabu_it
    Disclosure

    VS Codeの人気拡張機能4つ(累計 1億2,850万インストール超 )に重大脆弱性が発見されました。 🙅 未修正 ・Live Server(72M)CVE-2025-65717(9.1) ・Markdown Preview Enhanced(8.5M) ・Code Runner(37M) 🙆‍♂️ 修正済み Microsoft Live Preview ✅ チェックリスト 1. 拡張機能一覧を開く 2. 上記を使っていたら更新or一時無効化 3. localhostサーバーは必要時だけ起動

    Post summary

    A critical vulnerability (CVE-2025-65717, CVSS 9.1) has been discovered in popular VS Code extensions Live Server, Markdown Preview Enhanced and Code Runner; users should update or disable the extensions while a patch is pending.

    351541329454.4K
    22.6K followersView on X
  • FUJISE Takumi@t_fujise
    Disclosure

    VSCodeプラグインの脆弱性、Live Server のローカルファイルが外部サーバーへと持ち出される脆弱性はセキュリティの教材みたいな簡単な仕組みで、localhost:5500を叩くだけという、言われてみれば確かにという感じ。

https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/

    Post summary

    The post highlights a simple vulnerability in the VSCode Live Server plugin that can exfiltrate local files via localhost:5500, and it links to an article detailing the issue.

    1301142.2K
    459 followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    VSCodeの人気拡張機能複数に脆弱性。Ox Security社報告。Code Runner (CVE-2025-65715)、Markdown Preview Enhanced (CVE-2025-65716)…Markdown Preview Enhanced (CVE-2025-65717)、Microsoft Live Preview(CVE未採番)。 https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    The article announces multiple newly identified CVEs affecting popular VSCode extensions, but does not provide exploit details, patches, or evidence of active exploitation.

    230751.7K
    7.1K followersView on X
  • ネオ@パソコンメモ|Web制作@neo_mypcmemo
    Patch

    これヤバいな Live Serverないと仕事にならないんだけど 何はともあれ速攻で停止させて替わりのものを探さないとだな https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability #Web制作 #LiveServer

    Post summary

    The user warns that the Live Server VS Code extension is vulnerable and urges users to stop using it immediately and seek an alternative.

    100822.3K
    87 followersView on X
  • Sofyan Setiawan@sofyansetiawann
    Disclosure

    3 ekstensi VSCode yang ada vulnerability: - Live Server (pencurian local file) - Markdown Preview Enhanced (open .md, eksekusi js di dalamnya) - Code Runner (paste config) References: https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/ http://ox.security/blog/cve-2025-65715-code-runner-vscode-rce/ http://ox.security/blog/cve-2025-65716-markdown-preview-enhanced-vscode-vulnerability/

    Post summary

    The text announces three VSCode extensions with vulnerabilities, detailing local file theft and JavaScript execution, but makes no mention of PoC, active exploitation, patches, or debunking.

    00033234
    3.2K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Critical VS Code Live Server flaw CVE-2025-65717 (CVSS 9.1) lets attackers steal source code and credentials via malicious links. Protect your workspace now. #VSCode #LiveServer #CyberSecurity #CVE202565717 #InfoSec #DevSecOps #AppSec https://securityonline.info/cve-2025-65717-critical-vulnerability-in-vs-codes-live-server-extension-puts-72-million-developers-at-risk-no-patch/

    Post summary

    A new critical flaw (CVE‑2025‑65717) in VS Code Live Server allows attackers to steal source code and credentials via malicious links, and currently no patch is available.

    00020311
    10.3K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical VS Code Extension Flaws Put 128M+ Installs at Risk of File Theft and Remote Code Execution High-to-critical vulnerabilities in popular VS Code extensions—Live Server (CVE-2025-65715), Code Runner (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview—can enable local file exfiltration, XSS via crafted Markdown, and RCE via malicious configs, impacting VS Code-compatible IDEs like Cursor and Windsurf. Patch/remove affected extensions and treat untrusted workspaces/configs/files as hostile to prevent lateral movement and secret theft (API keys, configs). 🎯 Target: Global/Developers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/critical-vscode-extension-vulnerabilities-could-lead-to-code-execution-and-data-theft

    Post summary

    The post highlights high‑to‑critical vulnerabilities (CVE‑2025‑65715‑17) in popular VS Code extensions that could lead to file theft and remote code execution, urging users to patch or remove the affected extensions and treat untrusted workspaces as hostile.

    00011119
    174 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    VS Code の 4 件のエクステンションに深刻な脆弱性:累計インストール数は 1億2,500万回を超える https://iototsecnews.jp/2026/02/18/critical-flaws-found-in-four-vs-code-extensions-with-over-125-million-installs/ 公表された問題の背景にあるのは、localhost 上のサービスやローカル・ファイルへ過度にアクセスを許す、VS Code エクステンション設計です。CVE-2025-65717/CVE-2025-65716 では、悪意の Web サイトや .md ファイルを通じて JavaScript が実行され、ローカル開発サーバやポートが探索され、機密情報が外部に送信されます。また、CVE-2025-65715 では settings.json の改変により任意コード実行が成立します。拡張機能の権限分離や入力検証が不十分であった点が、ラテラル・ムーブメントの足掛かりとなっています。ご利用のチームは、ご注意ください。よろしければ、VS Code での検索結果も、ご参照ください。 #CodeRunner #CVE202565715 #CVE202565716 #CVE202565717 #Extension #LiveServer #MarkdownPreviewEnhanced #Microsoft #VSCode #Vulnerability

    Post summary

    Four VS Code extensions contain critical flaws that enable remote code execution through malicious JavaScript or settings.json tampering, potentially exposing local development servers and sensitive data.

    01000164
    485 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    VS Codeの主要な拡張機能4件で危険性のある脆弱性-最大1.2億に影響(CVE-2025-65717,CVE-2025-65715,CVE-2025-65716) https://rocket-boys.co.jp/security-measures-lab/four-major-vscode-extensions-hit-by-critical-flaws-affecting-up-to-120-million-installs-cve-2025-65715-cve-2025-65716-cve-2025-65717/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces critical vulnerabilities in four major VS Code extensions affecting up to 120 million installs, but does not provide PoC, exploit code, or patch details.

    00010158
    319 followersView on X
  • Natsuki@natch_engr
    Disclosure

    Live Serverを立てていると、簡単にローカルファイルをクロールできてしまう https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/

    Post summary

    The post notes that running Live Server in VSCode allows local file crawling, indicating a vulnerability in CVE‑2025‑65717, but no PoC, patch, or exploitation details are provided.

    10000250
    613 followersView on X
  • misaki|Webデザイナー@misakidesign_i
    Disclosure

    VS CodeのLive Server拡張機能 使用中に悪意あるJavaScriptが仕込まれたサイトにアクセスするだけで 外部からローカルファイル窃取可能な脆弱性 対策は ・他の安全なローカルサーバーツール使用 ・使用中に不用意に外部サイトを開かない ・使わないとき停止 などでしょうか https://www.ox.security/blog/cve-2025-65717-live-server-vscode-vulnerability/

    Post summary

    A newly disclosed vulnerability (CVE‑2025‑65717) in VS Code’s Live Server extension allows local file theft via malicious JavaScript, with recommended mitigations but no patch yet.

    00010435
    144 followersView on X
  • 𓊈𒆜🅲🆁🅸🆂🆃🅸🅰🅽 𒆜𓊉@Cris7ianJCC
    Disclosure

    Detalles de las Vulnerabilidades: CVE-2025-65717 (CVSS 9.1): En Live Server, permite a los atacantes exfiltrar archivos locales al engañar a un desarrollador para que visite un sitio web malicioso.

    Post summary

    The text announces CVE‑2025‑65717 as a high‑severity vulnerability in Live Server that allows local file exfiltration through a social‑engineering trick, with no mention of PoC, exploit, or mitigation.

    1000062
    662 followersView on X
  • Autumn Good@autumn_good_35
    General

    『Three were assigned CVEs – CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717 – totaling over 120 million downloads and posing a significant threat to developers worldwide.』 Four Vulnerabilities Expose a Massive Security Blind Spot in IDE Extensions https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    Three CVEs (CVE‑2025‑65715 through CVE‑2025‑65717) have been assigned and collectively have seen over 120 million downloads, indicating a significant threat to developers.

    00001450
    6.7K followersView on X
  • Grok@grok
    Disclosure

    1. **How it works**: Vulnerabilities exploit localhost servers or crafted files. E.g., Live Server (CVE-2025-65717) lets malicious sites steal files from its dev server; Markdown Preview Enhanced (CVE-2025-65716) runs arbitrary JS via .md files; Code Runner (CVE-2025-65715) enables code exec via settings tweaks; Microsoft Live Preview allowed file access (now fixed). 2. **Why it matters**: These affect 125M+ installs, risking data theft, code execution, and lateral attacks from a single flaw, threatening devs and orgs. 3. **Potential impacts on existing plugins**: Could enable chaining attacks to compromise other extensions, steal credentials, or spread malware across VS Code ecosystem if not mitigated via updates/uninstalls.

    Post summary

    The text discloses that several CVE-2025-65715/16/17 vulnerabilities in VS Code extensions allow file theft, code execution, and lateral movement, with patches or updates needed to remediate.

    00000325
    8.0M followersView on X
  • iototsecnews@iototsecnews
    General

    @__kokumoto 元記事の CVE-2025-65717 は Live Server の誤植ですかね🤔 https://nvd.nist.gov/vuln/detail/CVE-2025-65717

    Post summary

    The tweet speculates that CVE-2025-65717 might be a typo related to Live Server, but offers no additional technical or actionable information.

    0000094
    484 followersView on X
  • 如月 好葉@konoha_zilf
    Disclosure

    VScodeの脆弱性そのものはCVSSでクリティカル出してるので普通にヤバいのに、なんでこんなインプレ目的のカス記事に CVE-2025-65717 – Live Server Severity: Critical (CVSS 9.1) IDE: VS Code Extension: Live Server Affected Versions: All versions of Live Server Impact: Data exfiltration

    Post summary

    The text discloses a critical vulnerability (CVE-2025-65717) in the VS Code Live Server extension, noting its CVSS score and potential for data exfiltration, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000228
    1.4K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 125M+ VS Code Installs at Risk: 4 Popular Extensions Enable File Exfiltration & Remote Code Execution OX Security disclosed high/critical flaws across Live Server (CVE-2025-65717), Code Runner (CVE-2025-65715), and Markdown Preview Enhanced (CVE-2025-65716), plus an issue in Microsoft Live Preview, enabling attacker-triggered local file exfiltration and in some cases RCE via malicious content/preview/localhost abuse. This matters because IDE extensions run in trusted developer environments—turning a single booby-trapped project or link into a high-impact entry point for source-code theft and workstation compromise. 🎯 Target: Global/Developers & Software Teams #️⃣ Category: #Vulnerability #CyberIntel #BlueTeam 🔗 URL: https://securityaffairs.com/188185/security/vs-code-extensions-with-125m-installs-expose-users-to-cyberattacks.html

    Post summary

    OX Security has disclosed critical CVEs affecting popular VS Code extensions that enable local file exfiltration and, in some cases, remote code execution, posing a significant risk to developers worldwide.

    00000178
    174 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Disclosure

    The security issues impact Code Runner (CVE-2025-65715), Markdown Preview Enhanced (CVE-2025-65716), Markdown Preview Enhanced (CVE-2025-65717), and Microsoft Live Preview (no identifier assigned). https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

    Post summary

    A news article discloses new security vulnerabilities affecting popular VS Code extensions such as Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview.

    00000178
    911 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    Three high to critical vulns in VSCode. Info, incl. fixes, at SecAlerts: CVE-2025-65715: https://secalerts.co/vulnerability/CVE-2025-65715 CVE-2025-65716, CVSS 8.8: https://secalerts.co/vulnerability/CVE-2025-65716 CVE-2025-65717, CVSS 9.1: https://secalerts.co/vulnerability/CVE-2025-65717 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #vscode https://t.co/k7p5Dk2kFG

    Post summary

    Three high‑to‑critical VSCode vulnerabilities are announced with links to fix information; no PoC, exploit code, or evidence of active exploitation is mentioned.

    00000172
    796 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    I disclosed these vulnerabilities and got issued 3 out of 4 CVEs CVE-2025-65715: Code Runner (37M+) CVE-2025-65716: Markdown Preview Enhanced (8.5M+) CVE-2025-65717: Live Server (72M+) No CVE (but fixed): Live Preview by Microsoft (11M+) https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/

    Post summary

    The author announces the disclosure of three CVEs affecting popular IDE extensions, referencing a blog post for further information, but does not provide PoC, exploit code, patches, or evidence of active exploitation.

    00000151
    79 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appritwickdeylive_server-visual_studio_code-

Explore more