GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
Fixed in: VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1
details
- Finding IDs
- F-VSCODE-COPILOT-001
- CVE
- CVE-2026-21523
- Status
- patched
- Fixed in
- VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1
- Recorded credit
- MSRC acknowledgement: Oleh Konko with 1seal
- Note
- MSRC: GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability. MSRC revision history added acknowledgements on 2026-04-20 as an informational change; official acknowledgement lists Oleh Konko with 1seal. caveat: the public MCP-specific advisory GHSA-6xq8-9qf3-p6qv maps to CVE-2026-21518, so exact local finding-to-CVE mapping for F-VSCODE-MCP-001 vs CVE-2026-21523 depends on the private MSRC thread.
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
F-VSCODE-COPILOT-001: Needs source detail. Public CVE credit is recorded, but its multiple advisory variants do not establish this finding's exact mechanism. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-VSCODE-COPILOT-001
Security area (1seal assessment): Unclassified. Public CVE credit is recorded, but its multiple advisory variants do not establish this finding's exact mechanism. Reviewed 24 Sep 2026.