Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Microsoft AI agent tooling flaws: Semantic Kernel file write and Copilot command injection

Multiple vulnerabilities were disclosed in Microsoft's AI agent development tooling, including an arbitrary file write in the Semantic Kernel .NET SDK's SessionsPythonPlugin (fixed in Microsoft.SemanticKernel.Core 1.71.0) and command injection and TOCTOU race condition flaws in GitHub Copilot with Visual Studio and Visual Studio Code that allow privilege elevation, security feature bypass, or code execution over a network.

Disclosed 6 February 2026 · Record updated 13 September 2026

Impact

Attackers could write arbitrary files via the Semantic Kernel SessionsPythonPlugin file upload/download functions, and could elevate privileges, bypass a security feature, or execute code over a network through GitHub Copilot integrations with Visual Studio and Visual Studio Code.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25592
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21257
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21518
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21523