CVE-2026-70335ImportantRevised 2 Sep
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Assessment
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
- Severity
- Important
- CVSS base score
- 7.8CVSS:3.1/
AV:L/ AC:L/ PR:N/ UI:R/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.5%Higher than 37.5% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation More Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- GitHub Copilot and Visual Studio Code
- Weakness
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 2 Sep 2026Affected software updated with new package information.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Developer Tools1 affected product
- Visual Studio Code