ZeroHour

CVE-2026-81381

mass

Insufficiently Protected Credentials in GitHub Copilot and Visual Studio Code

CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
AI analysis

CVE-2026-81381 is a credential-protection flaw (CWE-522) in GitHub Copilot and Visual Studio Code, addressed by Microsoft's September 2026 Patch Tuesday release. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates that an unauthorized, unauthenticated attacker can trigger the issue over a network, but only with some user interaction. A successful attack has a high confidentiality impact, allowing disclosure of insufficiently protected credentials or other sensitive information, with no integrity or availability impact. Anyone running Visual Studio Code with the GitHub Copilot extension is in scope, which spans the very broad VS Code developer base. There is no public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates about a 0.6% chance of exploitation in the next 30 days, so exploitation is not confirmed.

What to do: Install the Visual Studio Code and GitHub Copilot fixes released with Microsoft's September 2026 Patch Tuesday, checking the Microsoft advisory for the exact fixed builds. Until patched, avoid using Copilot or stored GitHub credentials in VS Code over untrusted networks and warn users about unexpected interactive prompts. After updating, consider rotating or revoking GitHub personal access tokens and OAuth tokens if credential exposure is suspected.

Affected
Microsoft Visual Studio Code
Microsoft (GitHub) GitHub Copilot
Estimated exposure
masstens of millions of developer installations (VS Code is the most widely used code editor and Copilot is among its most-installed extensions) — VS Code's dominant developer market share and reported tens of millions of monthly active users make the installed base massive, though only users reachable by an attacker with the user-interaction precondition are exploitable in practice.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1