Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "vscode", "supply-chain"] ยท confidence: medium ยท severity: medium ยท affected_sectors: ["Technology", "Software Development"] ยท au_impact: true

CVE-2021-43891

Affected product: Visual Studio Code (trust-dialog bypass class)

Patched version: Historical CVE already fixed by Microsoft

Active exploitation: Referenced as a prior instance of the same trust-dialog bypass class

Assessment

CVE-2021-43891 relates to the trust-dialog bypass class in Visual Studio Code and is cited in Manifold's 'Universal Evil' research as an earlier example of the same category behind malicious Git configuration files making AI coding agents execute attacker code. It is an older, already-patched issue rather than a fresh disclosure in this window. It is recorded here because the September 2026 AI coding-agent research echoes its trust-model weakness as a practical caution for software supply chain integrity.