Impact
An improper neutralization of special elements within a command allows an authorized attacker to execute arbitrary commands and subsequently reveal sensitive information over the network. The flaw enables command injection that can lead to disclosure of data accessible through the extension’s network traffic.
Affected Systems
Microsoft Visual Studio Code Copilot Chat Extension is affected. The extension operates within Visual Studio Code, and no specific version range is provided in the data. The attack requires the attacker to have authorized access to the extension, such as an authenticated user or someone who can install or modify it.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated or local privileges, making the threat primarily a compromise of confidentiality rather than integrity or availability.
OpenCVE Enrichment