Insecure Initialization in GitHub Copilot and Visual Studio Code
CVE-2026-50519

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
19 June 2026

What is CVE-2026-50519?

The vulnerability arises from the insecure initialization of resources within GitHub Copilot and Visual Studio Code. This flaw can be exploited by unauthorized attackers to disclose sensitive information over the network, posing serious security risks to users and their projects. It is crucial for organizations using these products to remain vigilant and apply necessary security measures to safeguard their data.

Affected Version(s)

GitHub Copilot Chat 1.0.0 < 1.123.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.