VS Code 1.136.2 fixes RCE via remote agent host settings
Malicious workspace settings in untrusted repos could authorize a remote agent and expose local files.
By renderMalicious workspace settings in untrusted repos could authorize a remote agent and expose local files.
By renderA malicious workspace could redirect Azure DevOps code search traffic and the user's bearer token to an attacker-controlled host.
By renderCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By render