type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "vscode", "supply-chain"] ยท confidence: medium ยท severity: medium ยท affected_sectors: ["Technology", "Software Development"] ยท au_impact: true
CVE-2021-43891
Affected product: Visual Studio Code (trust-dialog bypass class)
Patched version: Historical CVE already fixed by Microsoft
Active exploitation: Referenced as a prior instance of the same trust-dialog bypass class
Assessment
CVE-2021-43891 relates to the trust-dialog bypass class in Visual Studio Code and is cited in Manifold's 'Universal Evil' research as an earlier example of the same category behind malicious Git configuration files making AI coding agents execute attacker code. It is an older, already-patched issue rather than a fresh disclosure in this window. It is recorded here because the September 2026 AI coding-agent research echoes its trust-model weakness as a practical caution for software supply chain integrity.