cbcvebase.
CVE-2026-21518
published 2026-02-10

CVE-2026-21518: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to…

PriorityP259high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.36%
68.4th percentile
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Affected

5 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_visual_studio_code_copilot_chat_extension>= 0.27.0 < 0.37.10.37.1
microsoftvisual_studio_code< 1.109.21.109.2
microsoftvisual_studio_code>= 1.0.0 < 1.110.11.110.1
msrcmicrosoft_visual_studio_code_copilot_chat_extension
msrcvisual_studio_code

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-21518 is a command injection vulnerability in GitHub Copilot and Visual Studio Code that allows an unauthorized attacker to bypass authentication via impersonation over a network. Monitor for anomalous network-based command injection attempts targeting VSCode or GitHub Copilot processes.
  • The security feature bypassed is authentication — successful exploitation allows impersonation. Detect unexpected authentication bypass or identity impersonation events originating from VSCode or Copilot network activity.
  • ·No public exploit exists as of the advisory date; exploitation is assessed as 'Less Likely' by Microsoft. Prioritize patching over detection urgency.
  • ·Fixes were made available starting February 11, 2026. Ensure VSCode is updated to at least v1.110 per the release notes referenced in the advisory.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.