Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
extension-plugin-hijackendpoint-software-vulnerabilitydata-exfiltration-methodlateral-movement-method

Ox Security disclosures of high-severity vulnerabilities in popular VSCode extensions

Updated 3mo agoFirst seen Feb 18, 20264 sources

Security researchers at Ox Security reported multiple high-to-critical vulnerabilities in widely used Visual Studio Code extensions—collectively exceeding 128 million downloads—that could enable local file exfiltration and code execution in developer environments. The issues highlighted include Live Server (CVE-2025-65717), Code Runner (CVE-2025-65715, referenced in reporting but not included as a CVE entry here), Markdown Preview Enhanced (CVE-2025-65716), and Microsoft Live Preview (no CVE cited in the reporting). Ox Security stated it attempted disclosure starting in June 2025 but did not receive responses from maintainers, warning that exploitation could support lateral movement, data theft, and system takeover in corporate networks where developer workstations are a pivot point.

The CVE records included in this set describe two of the extension flaws in more detail: CVE-2025-65717 (Live Server v5.7.9) allows attackers to exfiltrate files when a user interacts with a crafted HTML page, and CVE-2025-65716 (Markdown Preview Enhanced v0.8.18) can lead to arbitrary code execution via a crafted .md file (user interaction required). Other items in the feed are unrelated, covering a broad mix of independent vulnerabilities (e.g., Tenable Security Center command injection, LightLLM unsafe deserialization RCE, libvpx heap overflow affecting Firefox/Thunderbird, and multiple router/IoT hard-coded credential and command-injection issues) and should not be treated as part of the VSCode-extension disclosure story.

Share:
Ox Security disclosures of high-severity vulnerabilities in popular VSCode extensions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 18, 20264mo ago

ZoneMinder command injection vulnerability was publicly detailed

On Feb. 18, 2026, CVE-2025-65791 was updated with technical details describing a command injection flaw in ZoneMinder v1.36.34's web/views/image.php, where unsanitized input reaches exec(). The record added CVSS scoring, CWE classification, and a public reference, indicating unauthenticated remote exploitation with high impact.

Feb 17, 20264mo ago

OX Security publicly reported multiple high-severity VSCode extension flaws

OX Security disclosed multiple high-to-critical vulnerabilities in Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview, warning they could enable file theft, remote code execution, lateral movement, and full system compromise. The report said the issues also affect VSCode-compatible IDEs such as Cursor and Windsurf and impact extensions with more than 128 million combined downloads.

CVE details were enriched for VSCode extension flaws

On Feb. 17, 2026, the CVE records for CVE-2025-65716 and CVE-2025-65717 were updated with CVSS scoring, CWE classifications, and references to project repositories and third-party research. The updates characterized the flaws as high-severity issues affecting Markdown Preview Enhanced and Live Server.

Feb 16, 20264mo ago

MITRE received CVE-2025-65716 and CVE-2025-65717 records

MITRE received CVE records for two Visual Studio Code extension vulnerabilities: CVE-2025-65716 in Markdown Preview Enhanced and CVE-2025-65717 in Live Server. The issues involve arbitrary code execution via a crafted Markdown file and file exfiltration via a crafted HTML page, respectively.

Jun 1, 20251y ago

OX Security began disclosing VSCode extension flaws to maintainers

OX Security said it started responsible disclosure efforts in June 2025 for multiple vulnerabilities affecting popular Visual Studio Code extensions, but reported receiving no response from maintainers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.