← All updates

Devin Desktop · News date: · ACT

Type: Coding Agent

Devin Desktop fixes a critical inherited VS Code security bypass

Your move: Update to 3.10.31 or later if you open workspaces you don't fully trust

Cognition released Devin Desktop version 3.10.31 on September 16, 2026. It fixes a bug in Restricted Mode, a feature meant to block certain workspace settings from running automatically. The bug, tracked as CVE-2026-81376, let a workspace slip past that block by writing the settings in a nested object format instead of the usual one. Microsoft found the same underlying flaw in Visual Studio Code itself and rated it a near-maximum severity score. Devin Desktop inherited the bug because it is built on a fork of VS Code. The release also makes your 10 most recently viewed sessions show their transcripts immediately when you return to them.

Why it matters

This is a real security fix, not just a feature update. Before the patch, opening an untrusted workspace or repo in Devin Desktop could let it bypass safety restrictions and run code or settings you did not approve. If you use Devin Desktop, update to version 3.10.31 or later now, especially if you ever open code from outside your own team.

Source: Devin Desktop Changelog ↗

Published by Agent Log. The summary reports the linked source; “Why it matters” and the verdict are Agent Log's interpretation.

More Devin Desktop updates →