CVE-2025-64660
published 2025-11-20CVE-2025-64660: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
PriorityP350high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.49%
38.5th percentile
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_studio_code | < 1.106.2 | 1.106.2 |
| microsoft | visual_studio_code | >= 1.0.0 < 1.106.2 | 1.106.2 |
| msrc | visual_studio_code | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
vendor_msrc·2025-11-11·CVSS 8.0
CVE-2025-64660 [HIGH] CWE-284 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
Description: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, privileges are required (PR:L) and user interaction is required (UI:R). How could an attacker exploit this remote code execution vulnerability?
An authenticated attacker could place a malicious file in the targeted repo. The user would then have to trust the file on Visual Studio Code and ask for assistance from GitHub Copilot.
GitHub Copilot and Visual Studio Code: GitHub Copilot and Visual Studio Code
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Lates
GHSA
GHSA-j8xq-6qq7-vfv7: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature over a network
ghsa_unreviewed·2025-11-21
CVE-2025-64660 [MEDIUM] CWE-284 GHSA-j8xq-6qq7-vfv7: Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature over a network
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature over a network.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21518 [HIGH] CVE-2026-21518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21518 :
Visual Studio Code vulnerability analysis and mitigation
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Source : NVD
## 8.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity MEDIUM Has Fix Added at: Feb 11, 2026
Windows Severity MEDIUM Has Fix Added at: Feb 11, 2026
Linux Sever
Wiz
CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-21523 [HIGH] CVE-2026-21523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21523 :
Visual Studio Code vulnerability analysis and mitigation
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
Source : NVD
## 8
Score
Published February 10, 2026
Severity HIGH
CNA Score 8.0
Affected Technologies
Visual Studio Code
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:microsoft:visual_studio_code
Sources
Linux Severity HIGH Has Fix Added at: Feb 11, 2026
Windows Severity HIGH Has Fix Added at: Feb 11, 2026
Linux Severity HIGH Has Fix Added at: Feb 12, 2026
Windows Severity
2025-11-20
Published