OS Command Injection in GitHub Copilot and Visual Studio Code
An improper neutralization of special elements in os commands vulnerability in GitHub Copilot and Visual Studio Code allows unauthorized attackers to elevate privileges locally.
Disclosed 11 August 2026 · Record updated 13 September 2026
Impact
Unauthorized attackers could elevate privileges locally on affected systems
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-70335
