Command Injection Vulnerability in GitHub Copilot and Visual Studio Code
CVE-2026-23653

5.7MEDIUM

What is CVE-2026-23653?

The vulnerability in GitHub Copilot and Visual Studio Code arises from improper neutralization of special elements within commands, allowing an authorized attacker to exploit the system. This exploitation can lead to unauthorized information disclosure over a network, posing a significant risk to the security of sensitive data. Users of these products should take caution and consider applying available patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Microsoft Visual Studio Code CoPilot Chat Extension 0.27.0 < 0.37.3

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.