Hidden Install Settings Let Malicious MCP Links Execute Code. Microsoft patched a high-severity flaw in Visual Studio Code after researchers found attackers could hide malicious settings inside MCP server install links, giving them persistent access to developer machines through what appeared to be routine artificial intelligence tool installations.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/microsoft-code-editor-flaw-lets-attackers-hijack-developer-pcs-a-31775
![]()

