Command Injection Vulnerability in Visual Studio Code CoPilot Chat Extension by Microsoft
CVE-2025-62222
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-62222?
The Visual Studio Code CoPilot Chat Extension is subject to a command injection vulnerability, which permits unauthorized users to inject and execute arbitrary code remotely. This flaw arises from improper neutralization of special elements in command strings. If exploited, this vulnerability could enable attackers to compromise the integrity and confidentiality of the system. Users and organizations utilizing the affected extension should take proactive steps to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microsoft Visual Studio Code CoPilot Chat Extension Unknown 0.27.0 < 0.32.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved