CVE-2025-65717

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ritwickdey:live_server:*:*:*:*:*:visual_studio_code:*:*

History

No history.

Information

Published : 2026-02-16 16:19

Updated : 2026-02-25 18:43


NVD link : CVE-2025-65717

Mitre link : CVE-2025-65717

CVE.ORG link : CVE-2025-65717


JSON object : View

Products Affected

ritwickdey

  • live_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')