CVE-2026-81380: GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Published Sep 8, 2026
·Updated
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Other sources
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio Code<1.136.2
1.136.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The published vector indicates that exploitation can be performed over a network without attacker privileges, but requires user interaction and has high attack complexity.
2
What is the expected security impact if exploitation succeeds?
The vulnerability is rated as having high confidentiality impact. No integrity or availability impact is indicated in the published vector.