CVE-2026-41109 Details
Description
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
A vulnerability allowing unauthorized attackers to bypass security features over the network has been identified in GitHub Copilot and Visual Studio Code. This issue arises from improper neutralization of special elements in output, which can be exploited to manipulate user input or external content. As a result, attackers can bypass safeguards that validate file paths and require user approval for sensitive locations, potentially allowing unauthorized changes to protected files.
Users are advised to update to the latest version of Visual Studio Code, which includes a security update addressing this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft visual studio code | < 1.119.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | [email protected] |
| Aug 10, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |