Command Injection Vulnerability in GitHub Copilot and Visual Studio Code
CVE-2026-81380

5.3MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81380?

A vulnerability exists in GitHub Copilot and Visual Studio Code due to improper handling of special elements in commands. This flaw enables unauthorized attackers to execute commands that may lead to unauthorized information disclosure over a network, potentially compromising user data. Developers are advised to review and implement the latest security patches provided by Microsoft to mitigate this risk.

Affected Version(s)

Visual Studio Code 1.0.0 < 1.136.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.