Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-70335

Опубликовано: 11 авг. 2026
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

FAQ

How could an attacker exploit this vulnerability?

An attacker could embed malicious instructions in content that the AI agent processes, such as a web page, a repository file, or a tool response. When a user runs the agent against that content, the injected instructions could cause the agent to run commands on the user's machine without prompting for confirmation. Successful exploitation could allow the attacker to execute code in the context of the signed-in user. User interaction is required and the attack is carried out locally; no authentication is required for the attacker to supply the content.

Обновления

ПродуктСтатьяОбновление
Visual Studio Code

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

EPSS

Процентиль: 36%
0.00421
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 месяца назад

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
github
около 1 месяца назад

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

EPSS

Процентиль: 36%
0.00421
Низкий

7.8 High

CVSS3