CyberRota Analysis
AI-GeneratedGitHub Copilot and Visual Studio Code are vulnerable to an OS command injection flaw that permits unauthorized attackers to escalate privileges locally. This high-severity vulnerability (CVSS 7.8) poses a significant risk to users who rely on these tools for development, making it essential for organizations utilizing these products to prioritize immediate remediation efforts.
CVE
CVE-2026-70335
Severity
HIGH
CVSS
7.8
EPSS
0.47%
GitHub
Original NVD Description
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Related CVEs
Other vulnerabilities affecting the same vendor(s)