SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81380

MEDIUM · CVSS 5.3 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

GitHub Copilot and Visual Studio Code are vulnerable to command injection due to improper handling of special elements, which could allow an unauthorized attacker to disclose sensitive information over a network. Organizations using these tools should prioritize addressing this vulnerability to mitigate potential data exposure risks. This is particularly critical for development teams and enterprises that rely heavily on GitHub services for their coding and collaboration processes.

CVE
CVE-2026-81380
Severity
MEDIUM
CVSS
5.3
EPSS
0.63%
GitHub

Original NVD Description

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.