Injection Flaw in GitHub Copilot and Visual Studio by Microsoft
CVE-2026-41109
8.8HIGH
What is CVE-2026-41109?
An injection vulnerability exists in GitHub Copilot and Visual Studio that allows a malicious actor to exploit improper handling of special elements in output. This weakness can enable unauthorized access, allowing an attacker to bypass established security measures over a network, thereby compromising the integrity of the affected systems.
Affected Version(s)
Visual Studio Code 1.0.0 < 1.119.1