CVE-2026-41613: Microsoft Visual Studio Code MCP Install Dialog Flaw (Envade)
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Visual Studio Code, a popular code editor, was targeted by malicious extensions on the Open VSX marketplace that exfiltrated developer data. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity remote code execution vulnerability, CVE-2026-45659 (CVSS 8.8), affecting Microsoft SharePoint…
Microsoft Visual Studio Code has a vulnerability (CVE-2026-41613) in its MCP install dialog that allows code execution via crafted deeplinks.