CVE-2026-81381 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Information published.
EPSS 0.01 CVE-2026-64654 GitHub US
Information published.
EPSS 0.00 CVE-2026-64652 GitHub US
Information published.
EPSS 0.01 CVE-2026-64653 GitHub US
Information published.
EPSS 0.00 CVE-2026-59831 GitHub US
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-41109 GitHub US
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47282 GitHub US
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45482 Microsoft GitHub US