CVE-2026-41109: GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Other sources
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.128.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41109?
CVE-2026-41109 has been assigned a severity rating that indicates a potential security feature bypass in GitHub Copilot and Visual Studio Code.
How do I fix CVE-2026-41109?
To fix CVE-2026-41109, ensure that you update GitHub Copilot and Visual Studio Code to the latest version as provided in the official updates.
What vulnerability type is CVE-2026-41109 classified as?
CVE-2026-41109 is classified as a security feature bypass vulnerability due to improper neutralization of special elements in output.
Which software versions are affected by CVE-2026-41109?
CVE-2026-41109 affects various versions of GitHub Copilot and Microsoft Visual Studio Code prior to the security fixes.
Who is responsible for addressing CVE-2026-41109?
Microsoft is responsible for addressing CVE-2026-41109 as it affects the products they maintain, specifically Visual Studio Code.