Command Injection in GitHub Copilot and Visual Studio Code Allows Information Disclosure
AI analysis
CVE-2026-81380 is a command injection vulnerability (CWE-77) in GitHub Copilot and Visual Studio Code in which special elements used in commands are improperly neutralized. An unauthorized attacker can trigger it remotely over a network, but exploitation requires high attack complexity and user interaction, meaning a user must be led into letting crafted input reach a command executed by Copilot or VS Code. Successful exploitation yields information disclosure only, with high confidentiality impact and no integrity or availability impact. Anyone running affected, unpatched versions of Visual Studio Code with the GitHub Copilot integration is potentially affected, though the available data does not specify exact version ranges. There is no known public proof-of-concept, no CISA KEV listing, and a low EPSS exploitation probability (0.6% over 30 days); per related coverage, Microsoft shipped fixes among its September 2026 Patch Tuesday updates.
What to do: Update Visual Studio Code and the GitHub Copilot extension to the latest patched releases distributed through Microsoft's September 2026 security updates (fixed version numbers are not listed in this data, so verify via the VS Code Extensions panel and Microsoft's advisory). Until patched, exercise caution when letting Copilot process untrusted content such as unfamiliar repositories, files, or chat input, since user interaction is part of the attack path.
Affected
| Microsoft (GitHub) GitHub Copilot for Visual Studio Code | — |
| Microsoft Visual Studio Code | — |
Estimated exposure
masstens of millions of developer installations (VS Code holds roughly 70%+ of developer-editor market share and Copilot has a multimillion-user subscriber base) — VS Code's dominant code-editor market share in public developer surveys and GitHub Copilot's multimillion-user adoption imply tens of millions of potentially exposed installations, though actual exploitability is limited by the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.