Description
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-08-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthorized attacker can bypass a security feature in the Microsoft Visual Studio Code CoPilot Chat Extension over a network. The flaw stems from an insufficient or missing authorization check, exposing the extension to privilege escalation or unauthorized data access depending on the protected functionality. Because the vulnerability is a feature bypass, the potential impact includes disclosure of restricted information or manipulation of the extension’s behavior.

Affected Systems

Microsoft Visual Studio Code CoPilot Chat Extension is the affected product. No specific version information is provided, indicating that all released revisions of the extension may be susceptible until Microsoft releases a patch. The extension operates within Visual Studio Code and interacts with the local system and network channels.

Risk and Exploitability

The CVSS score of 7.1 signals moderate to high severity. The EPSS score is reported as less than 1 percent, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring an attacker to communicate with the extension over a network session. Exploitation would require the extension to be active on the target machine and an adversary to offer a crafted request that triggers the missing authorization check.

Generated by OpenCVE AI on August 22, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the CoPilot Chat Extension to the latest release that includes the security fix available in the Visual Studio Code marketplace.
  • If a fix is not yet available, uninstall or disable the extension to eliminate the attack surface.
  • Monitor Microsoft Security Response Center advisories and apply any official patch as soon as it is released.
  • Review network traffic involving the extension to ensure no unexpected connections are allowed to the local host.

Generated by OpenCVE AI on August 22, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft github Copilot Chat
Microsoft visual Studio Code
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:microsoft:github_copilot_chat:-:*:*:*:*:visual_studio_code:*:*
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*
Vendors & Products Microsoft github Copilot Chat
Microsoft visual Studio Code

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
Title CoPilot Chat Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code Copilot Chat Extension
CPEs cpe:2.3:a:microsoft:visual_studio_code_copilot_chat_extension:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code Copilot Chat Extension
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Github Copilot Chat Visual Studio Code Visual Studio Code Copilot Chat Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:42.268Z

Reserved: 2026-07-22T18:16:01.898Z

Link: CVE-2026-65675

cve-icon Vulnrichment

Updated: 2026-08-12T13:50:38.207Z

cve-icon NVD

Status : Modified

Published: 2026-08-11T17:18:55.427

Modified: 2026-08-28T20:19:29.913

Link: CVE-2026-65675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:30:17Z

Weaknesses