CVE-2026-70335: GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Other sources
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.132.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70335?
CVE-2026-70335 has a severity rating of high with a score of 7.8.
How do I fix CVE-2026-70335?
To fix CVE-2026-70335, users should update to the latest versions of GitHub Copilot and Visual Studio Code as per the vendor's guidelines.
What is the risk associated with CVE-2026-70335?
CVE-2026-70335 has a risk rating of 68, indicating a significant potential impact due to privilege elevation.
What type of vulnerability is CVE-2026-70335?
CVE-2026-70335 is classified as an OS Command Injection vulnerability allowing privilege escalation.
Who is affected by CVE-2026-70335?
CVE-2026-70335 affects users of GitHub Copilot and Microsoft Visual Studio Code.