VS Code MCP install flow had hidden fields, and it just got a CVE
Oasis Security Research disclosed CVE-2026-41613, a VS Code MCP install flow that hid five fields from the preview dialog. The fix is in 1.119.1, and the install link is still the most common attack path.