Disclosure summary
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Source-reported weakness categories
CWE-78
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Aug
Open original source · Updated Sep 02, 2026
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 7.8
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | Visual Studio Code | (MSRC status code 3) |
Vendor remediation references
- Release Notes · build 1.132.1 · product IDs 11622
- Vendor guidance · product IDs 11622
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2026-08-11T03:00:00-04:00
MODIFIED 2026-09-02T03:00:00-04:00
INGESTED 2026-10-08T12:40:37-04:00