CVE-2026-70335 PUBLISHED

GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

Assigner: microsoft
Reserved: 04.08.2026 Published: 11.08.2026 Updated: 11.08.2026

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS Score: 7.8

Product Status

Vendor Microsoft
Product Visual Studio Code
Versions
  • affected from 1.0.0 to 1.132.1 (excl.)

References

Problem Types