Impact
The vulnerability is a command injection flaw due to improper neutralization of special elements in GitHub Copilot and Visual Studio Code. When triggered, an attacker can cause the application to execute unintended commands, allowing them to read data or metadata across the network. This flaw is categorized under CWE-77 and results in unauthorized information disclosure rather than arbitrary code execution.
Affected Systems
The affected product is Microsoft Visual Studio Code. The vulnerability applies to any instance that integrates the GitHub Copilot feature. Specific version ranges are not listed in the advisory, so any current release that includes Copilot integration should be considered vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not yet listed in CISA’s KEV catalog, suggesting there have been no confirmed widespread attacks. Based on the available data, the attack scenario is likely local or involves an attacker who can supply a Copilot prompt; however, the impact is limited to information disclosure over a network. The lack of a publicly available exploit and the absence in the KEV reduce the immediacy of risk but warrant timely remediation.
OpenCVE Enrichment