Insufficiently protected credentials in Visual Studio Code - CVE-2026-81381
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in GitHub Copilot and Visual Studio Code when handling a user\'s work account sign-in access token. A remote attacker can obtain the token to disclose sensitive information.
User interaction is required.