CVE-2025-53773
published 2025-08-12CVE-2025-53773: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to…
PriorityP349high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.57%
83.3th percentile
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio_2022_version_17.14 | >= 17.14.0 < 17.14.12 | 17.14.12 |
| microsoft | visual_studio_2022 | >= 17.14.0 < 17.14.12 | 17.14.12 |
| msrc | microsoft_visual_studio_2022_version_17.14 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3m2x-p87c-pwv6: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke
ghsa_unreviewed·2025-08-12
CVE-2025-53773 [HIGH] CWE-77 GHSA-3m2x-p87c-pwv6: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
Microsoft
GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2025-08-12·CVSS 7.8
CVE-2025-53773 [HIGH] CWE-77 GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
Description: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of this vulnerability requires that a user trigger the payload in the application.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out loc
No detection rules found.
No public exploits indexed.
arXiv
PlanTwin: Privacy-Preserving Planning Abstractions for Cloud-Assisted LLM Agents
arxiv_fulltext·2026-03
PlanTwin: Privacy-Preserving Planning Abstractions for Cloud-Assisted LLM Agents
: Privacy-Preserving Planning Abstractions for Cloud-Assisted LLM Agents
Guangsheng Yu^1, Qin Wang^1,2, Rui Lang^1, Shuai Su^1, Xu Wang^1
^1University of Technology Sydney | ^2CSIRO Data61
Australia
## Abstract
Cloud-hosted large language models (LLMs) have become the de facto planners in agentic systems, coordinating tools and guiding execution over local environments. In many deployments, however, the environment being planned over is private, containing source code, files, credentials, and metadata that cannot be exposed to the cloud. Existing solutions address adjacent concerns, such as execution isolation, access control, or confidential inference, but they do not control what cloud planners observe during planning: within the permitted scope, raw environment state is still expose
arXiv
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
arxiv_fulltext·2026-02-10
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
Oleg Brodt^1, Elad Feldman^2, Bruce Schneier^3, Ben Nassi^2
^1Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev
^2School of Electrical and Computer Engineering, Tel Aviv University
^3Harvard Kennedy School, Harvard University, and Munk School, University of Toronto
## Abstract
Prompt injection was initially framed as the large language model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated input-manipulation exploits into multistep attack mechanisms that resemble malware.
In this paper, we argue that prompt injections evolved into promptware, a new
arXiv
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
arxiv_fulltext·2026-01-24
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
Narek Maloyan and Dmitry Namiot
page1
arabic
fancy
fancy
[R]
0pt
## Abstract
The proliferation of agentic AI coding assistants, including Claude Code, GitHub Copilot, Cursor, and emerging skill-based architectures, has fundamentally transformed software development workflows. These systems leverage Large Language Models (LLMs) integrated with external tools, file systems, and shell access through protocols like the Model Context Protocol (MCP). However, this expanded capability surface introduces critical security vulnerabilities. In this Systematization of Knowledge (SoK) paper, we present a comprehensive analysis of prompt injection attacks targe
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
blogs_bleepingcomputer·2025-08-12·CVSS 7.2
[HIGH] Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
## Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
## Lawrence Abrams
44 Elevation of Privilege Vulnerabilities
35 Remote Code Execution Vulnerabilities
18 Information Disclosure Vulnerabilities
4 Denial of Service Vulnerabilities
9 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released on Patch Tuesday. Therefore, the number of flaws does not include Mariner, Azure, and Microsoft Edge bugs fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5063878 & KB5063875 cumulative updates and the Windows 10 KB5063709 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one
2025-08-12
Published