Description
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update
AI Analysis

Impact

A vulnerability in the credential handling of GitHub Copilot and Visual Studio Code allows an unauthorized attacker to read sensitive information over the network. The flaw arises because credentials are not adequately protected, resulting in an information disclosure that can leak passwords or other secrets. The weakness is classified as CWE-522, which describes inappropriate or insufficient protection of credentials. The impact is limited to unauthorized disclosure of data; it does not enable code execution or system compromise, but the leaked data may lead to further attacks against services or accounts the compromised credentials access.

Affected Systems

Microsoft Visual Studio Code and the integrated GitHub Copilot extension are affected. The vulnerability applies to any installation that uses the default credential storage mechanism of Visual Studio Code without additional protection. No specific version numbers are listed, so all current versions before the vendor patch are presumed vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate impact and the documented exploitation possibility is over the network from an unauthorized attacker. The EPSS score is not available, but the lack of a CISA KEV listing suggests that widespread exploitation has not yet been observed. The likely attack vector is a network‑based attack in which an attacker intercepts or breaches the credential transport. Users who store credentials locally or rely on automatic caching are at particular risk. Prompt patching mitigates the risk as the vulnerability is easy to exploit once credentials are available.

Generated by OpenCVE AI on September 9, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Visual Studio Code update that includes the vendor fix for credential protection.
  • Update the GitHub Copilot extension to the newest release that addresses credential handling.
  • Remove or secure any cached or stored credentials that may be exposed by the legacy storage mechanism.

Generated by OpenCVE AI on September 9, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Title GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-522
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:54.533Z

Reserved: 2026-08-26T18:46:26.214Z

Link: CVE-2026-81381

cve-icon Vulnrichment

Updated: 2026-09-08T20:18:45.635Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:54.470

Modified: 2026-09-15T13:31:41.243

Link: CVE-2026-81381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:15:16Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials