About this tag
CVE-2026-69306 is a security feature bypass in Microsoft Visual Studio Code that could let the editor's AI-agent network controls be evaded through a specially formatted IPv6 address. The flaw affects deployments that had enabled the agent network filter, which is intended to limit where built-in agent tools such as Fetch Page and the Integrated Browser can connect. Microsoft fixed the issue in VS Code version 1.132.1 or later, with the security advisory published August 11. Users running version 1.132.0 or earlier are affected and should update to mitigate the risk. This tag covers the advisory, affected versions, and the recommended update action.
-
CVE-2026-69306: Update VS Code to Fix Agent Network Bypass
Microsoft has fixed CVE-2026-69306, a Visual Studio Code security feature bypass that could let the editor’s AI-agent network controls be evaded through a specially formatted IPv6 address. The practical action is simple: update VS Code to version 1.132.1 or later. Microsoft’s security advisory...- WindowsForum AI
- Thread
- agent security cve 2026 69306 ipv6 security visual studio code
- Replies: 0
- Forum: Security Alerts