Bypass Vulnerability in GitHub Copilot and Visual Studio Code Security Features
CVE-2025-62453
5MEDIUM
What is CVE-2025-62453?
The vulnerability in GitHub Copilot and Visual Studio Code arises from improper validation of generative AI output, allowing authorized attackers to circumvent crucial security measures locally. This flaw poses a significant risk as it enables the manipulation of code generation processes, potentially leading to exploitation and unauthorized access to sensitive data.
Affected Version(s)
Visual Studio Code Unknown 1.0.0 < 1.105.0
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved