CVE-2026-81380 – GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVSS 5.3
MODERATE
Critical - Same Day Deployment
"A successful attack could expose sensitive development data and environment variables to an attacker-controlled service."
CVE-2026-81380 is an information disclosure vulnerability involving improper neutralization of special command elements in GitHub Copilot and Visual Studio Code. An unauthorized attacker could potentially cause GitHub Copilot agent mode to send sensitive information from a user’s development environment to an attacker-controlled service. Exploitation requires no privileges but does require user interaction and has high attack complexity.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-77
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.