Description
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a command injection flaw due to improper neutralization of special elements in GitHub Copilot and Visual Studio Code. When triggered, an attacker can cause the application to execute unintended commands, allowing them to read data or metadata across the network. This flaw is categorized under CWE-77 and results in unauthorized information disclosure rather than arbitrary code execution.

Affected Systems

The affected product is Microsoft Visual Studio Code. The vulnerability applies to any instance that integrates the GitHub Copilot feature. Specific version ranges are not listed in the advisory, so any current release that includes Copilot integration should be considered vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not yet listed in CISA’s KEV catalog, suggesting there have been no confirmed widespread attacks. Based on the available data, the attack scenario is likely local or involves an attacker who can supply a Copilot prompt; however, the impact is limited to information disclosure over a network. The lack of a publicly available exploit and the absence in the KEV reduce the immediacy of risk but warrant timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Microsoft Visual Studio Code release that includes the patch.
  • If the patch is not yet available, temporarily disable GitHub Copilot extensions until an update is released.
  • Verify that no untrusted extensions or custom scripts are executed to mitigate potential command injection.

Generated by OpenCVE AI on September 9, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Title GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-77
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:53.891Z

Reserved: 2026-08-26T18:46:26.214Z

Link: CVE-2026-81380

cve-icon Vulnrichment

Updated: 2026-09-08T20:19:00.508Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:54.330

Modified: 2026-09-23T19:51:23.410

Link: CVE-2026-81380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:30:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')