Command injection flaws in GitHub Copilot and Visual Studio enable remote code execution
Two CVEs (CVE-2026-21256 and CVE-2026-21516) describe improper neutralization of special elements used in a command in GitHub Copilot, and in Visual Studio for one of them, allowing an unauthorized attacker to execute code over a network. Both are covered by Microsoft Security Response Center advisories.
Disclosed 10 February 2026 · Record updated 13 September 2026
Impact
An unauthorized attacker could execute code over a network against affected GitHub Copilot and Visual Studio installations.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21256
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21516
