Netskope Threat Labs

FILE-OTHER Microsoft Visual Studio Code Markdown Preview Enhanced extension command injection attempt

IPS-SWG

1 SID: 61803

First seen
February 2026
Last seen
February 2026

Detects documents exploiting CVE-2022-45025, a command injection in the Markdown Preview Enhanced extension for Visual Studio Code. The rule matches the import directives that run local files when the preview renders them.