Impact
The vulnerability arises from improper neutralization of special elements used in an operating‑system command within GitHub Copilot and Visual Studio Code. This oversight, classified as OS command injection (CWE‑78), enables an attacker with a local unauthenticated session to execute arbitrary system commands, thereby escalating privileges on the affected machine.
Affected Systems
Microsoft Visual Studio Code, including the GitHub Copilot extension. The exact product versions are not specified in the data, so the issue likely applies to all installed versions of VS Code that currently integrate the Copilot feature.
Risk and Exploitability
The CVSS score of 7.8 marks it as a high‑severity vulnerability, yet the EPSS score is reported as < 1%, indicating that exploitation is expected to be rare. Because the flaw can be exercised only after the attacker has obtained local access, the attack vector remains local, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment