CVE-2025-62453
published 2025-11-11CVE-2025-62453: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
PriorityP426medium5CVSS 3.1
AVLACLPRLUIRSUCNIHAN
EPSS
0.41%
33.0th percentile
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | < 1.105.0 | 1.105.0 |
| microsoft | visual_studio_code | >= 1.0.0 < 1.105.0 | 1.105.0 |
| msrc | visual_studio_code | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
vendor_msrc5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
vendor_msrc·2025-11-11·CVSS 5.0
CVE-2025-62453 [MEDIUM] CWE-1426 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Description: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Visual Studio Code sensitive file protections.
FAQ: According to the CVSS metric, the attack vector is local (AV:L), privileges are required (PR:L) and user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability?
The attack itself is carried out locally by a user with authentication to the targeted repo. An authenticated attacker co
GHSA
GHSA-6cp5-fpm8-87vg: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locall
ghsa_unreviewed·2025-11-11
CVE-2025-62453 [MEDIUM] CWE-693 GHSA-6cp5-fpm8-87vg: Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locall
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
blogs_bleepingcomputer·2025-11-11·CVSS 7.0
[HIGH] Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
## Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
## Lawrence Abrams
29 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
16 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include Microsoft Edge and Mariner vulnerabilities fixed earlier this month.
Today is also the first extended security update (ESU) for Windows 10, so if you are still utilizing the unsupported operating system, it is strongly advised that you upgrade to Windows 11 or enroll in the ESU program .
For those who are
Wiz
CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21518 [HIGH] CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21518 :
Visual Studio Code vulnerability analysis and mitigation
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Source : NVD
## 8.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity MEDIUM Has Fix Added at: Feb 11, 2026
Windows Severity MEDIUM Has Fix Added at: Feb 11, 2026
Linux Sever
Wiz
CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21523 [HIGH] CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21523 :
Visual Studio Code vulnerability analysis and mitigation
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
Source : NVD
## 8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.0
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity HIGH Has Fix Added at: Feb 11, 2026
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Linux Severity HIGH Has Fix Added at: Feb 12, 2026
Windows Severity
2025-11-11
Published