OS Command Injection in Visual Studio Code - CVE-2026-70335
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to command injection in GitHub Copilot and Visual Studio Code AI agent content processing when processing attacker-controlled content. A remote attacker can embed malicious instructions in a web page, repository file, or tool response to elevate privileges.
User interaction is required to run the agent against the crafted content, and the injected instructions may cause commands to run without prompting for confirmation.