CVE-2025-62453

CWE-693CWE-14264 documents4 sources
Severity
5.0MEDIUM
EPSS
0.0%
top 87.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11

Description

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:NExploitability: 1.3 | Impact: 3.6

Affected Packages2 packages

CVEListV5microsoft/visual_studio_code1.0.01.105.0

🔴Vulnerability Details

2
GHSA
GHSA-6cp5-fpm8-87vg: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locall2025-11-11
CVEList
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability2025-11-11

📋Vendor Advisories

1
Microsoft
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability2025-11-11