Command Injection Vulnerability in Visual Studio Code CoPilot Chat Extension by Microsoft
CVE-2025-62222
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-62222?
The Visual Studio Code CoPilot Chat Extension is subject to a command injection vulnerability, which permits unauthorized users to inject and execute arbitrary code remotely. This flaw arises from improper neutralization of special elements in command strings. If exploited, this vulnerability could enable attackers to compromise the integrity and confidentiality of the system. Users and organizations utilizing the affected extension should take proactive steps to mitigate this risk.
Affected Version(s)
Microsoft Visual Studio Code CoPilot Chat Extension Unknown 0.27.0 < 0.32.5