Impact
A vulnerability in the credential handling of GitHub Copilot and Visual Studio Code allows an unauthorized attacker to read sensitive information over the network. The flaw arises because credentials are not adequately protected, resulting in an information disclosure that can leak passwords or other secrets. The weakness is classified as CWE-522, which describes inappropriate or insufficient protection of credentials. The impact is limited to unauthorized disclosure of data; it does not enable code execution or system compromise, but the leaked data may lead to further attacks against services or accounts the compromised credentials access.
Affected Systems
Microsoft Visual Studio Code and the integrated GitHub Copilot extension are affected. The vulnerability applies to any installation that uses the default credential storage mechanism of Visual Studio Code without additional protection. No specific version numbers are listed, so all current versions before the vendor patch are presumed vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact and the documented exploitation possibility is over the network from an unauthorized attacker. The EPSS score is not available, but the lack of a CISA KEV listing suggests that widespread exploitation has not yet been observed. The likely attack vector is a network‑based attack in which an attacker intercepts or breaches the credential transport. Users who store credentials locally or rely on automatic caching are at particular risk. Prompt patching mitigates the risk as the vulnerability is easy to exploit once credentials are available.
OpenCVE Enrichment