Command Injection Vulnerability in GitHub Copilot and Visual Studio Code
CVE-2026-23653
5.7MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-23653?
The vulnerability in GitHub Copilot and Visual Studio Code arises from improper neutralization of special elements within commands, allowing an authorized attacker to exploit the system. This exploitation can lead to unauthorized information disclosure over a network, posing a significant risk to the security of sensitive data. Users of these products should take caution and consider applying available patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft Visual Studio Code CoPilot Chat Extension 0.27.0 < 0.37.3