CVE-2025-55319
published 2025-09-12CVE-2025-55319: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.85%
53.9th percentile
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | < 1.104.0 | 1.104.0 |
| microsoft | visual_studio_code | >= 1.0.0 < 1.104.0 | 1.104.0 |
| msrc | visual_studio_code | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-55319 is an AI command injection vulnerability in Agentic AI and Visual Studio Code allowing remote code execution over a network by an unauthorized attacker — monitor for unexpected process spawning or network-initiated code execution originating from VS Code Agentic AI components ↗
- →Microsoft rates exploitation as 'More Likely' for the latest software release — prioritize patching VS Code to v1.104 (released 2025-09-11) and monitor for exploitation attempts against Agentic AI features ↗
- →Fix is available in VS Code v1.104; reference the release notes at the linked URL to identify the patched version for detection baseline ↗
- ·The affected component is specifically 'Agentic AI and Visual Studio Code' — detections and mitigations should be scoped to environments where VS Code Agentic AI features are enabled or exposed over a network ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
vendor_msrc·2025-09-09·CVSS 8.8
CVE-2025-55319 [HIGH] CWE-77 Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
Description: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Agentic AI and Visual Studio Code: Agentic AI and Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely
Remediation: Release Notes
Reference: https://code.visualstudio.com/updates/v1_104?pubDate=20250911
GHSA
GHSA-gv2h-mcrv-w23w: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network
ghsa_unreviewed·2025-09-12
CVE-2025-55319 [HIGH] CWE-77 GHSA-gv2h-mcrv-w23w: Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21518 [HIGH] CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21518 :
Visual Studio Code vulnerability analysis and mitigation
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Source : NVD
## 8.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity MEDIUM Has Fix Added at: Feb 11, 2026
Windows Severity MEDIUM Has Fix Added at: Feb 11, 2026
Linux Sever
Wiz
CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21523 [HIGH] CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21523 :
Visual Studio Code vulnerability analysis and mitigation
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
Source : NVD
## 8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.0
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity HIGH Has Fix Added at: Feb 11, 2026
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Linux Severity HIGH Has Fix Added at: Feb 12, 2026
Windows Severity
2025-09-12
Published