HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-54981 — Inclusion of functionality from untrusted control sphere in Visual Studio Code -...

·Source: NIST NVD

Updated:

Executive Summary

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

Analysis

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. CVSS Score: 7.8. Published: 2026-08-11T17:18:03.780.

Indicators of Compromise (1)

CVE (1)
CVE-2026-54981
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats

LOWVulnerability

CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

<p><b>Bulletin ID:</b> 2026-082-AWS<br> <b>Scope:</b> AWS<br> <b>Content Type:</b> Important (requires attention)<br> <b>Publication Date:</b> 08/18/2026 10:00 AM PDT</p> <p><b>Description:</b></p> <p>OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in

CVE-2026-75897
AWS Security Bulletins
CRITICALVulnerability

NVD CRITICAL: CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their request...

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen containe

CVE-2026-75625
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows att...

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destru

CVE-2026-75130
NIST NVD