CVE-2026-50519 Details
Description
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
A vulnerability exists in GitHub Copilot and Visual Studio Code due to the initialization of a resource with an insecure default. This flaw allows unauthorized attackers to disclose information over a network. The vulnerability affects GitHub Copilot Chat and Visual Studio Code Copilot Chat, both of which are part of the Microsoft product family.
Users can download the security update for GitHub Copilot Chat from the GitHub Copilot release notes page. For Visual Studio Code, the security update is available on the Visual Studio Code download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50519 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft github copilot chat | All versions |
CPE
Remediation
| |
| microsoft visual studio code | < 1.123.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | Reanalysis | [email protected] |
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |