Improper Neutralization of Special Elements in Output Used by a Downstream Component in Visual Studio Code - CVE-2026-41109
Published: May 13, 2026
Visual Studio Code
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in GitHub Copilot and Visual Studio Code. A remote attacker can trick a victim to open a specially crafted package file and bypass the path validation safeguards, allowing changes to protected files without the user’s knowledge or consent.