CVE-2026-41109
- EPSS 0.06%
- Veröffentlicht 12.05.2026 16:58:55
- Zuletzt bearbeitet 15.05.2026 15:27:35
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21518
- EPSS 0.07%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 23.02.2026 17:23:27
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- EPSS 0.04%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 11.02.2026 21:41:36
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2026-21516
- EPSS 0.03%
- Veröffentlicht 10.02.2026 18:16:33
- Zuletzt bearbeitet 11.02.2026 21:40:45
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
CVE-2025-64671
- EPSS 0.12%
- Veröffentlicht 09.12.2025 17:56:06
- Zuletzt bearbeitet 12.12.2025 13:57:32
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.