Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23653

23
FAUCET Score

CVE-2026-23653 is a command injection vulnerability in GitHub Copilot and Visual Studio Code that permits authorized users to execute arbitrary commands and potentially disclose sensitive information over a network. The flaw stems from improper neutralization of special elements in command processing, allowing an attacker to manipulate input and gain unauthorized data access. The vulnerability carries a MEDIUM severity rating (CVSS 5.7) with a network-based attack vector requiring low complexity and low privileges, though user interaction is necessary. The primary impact is confidentiality compromise, with no integrity or availability effects. The FAUCET Risk Score of 33.0/100 suggests moderate concern. This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation in the wild. It remains in an inactive status on relevant vulnerability tracking lists, and community attention appears limited based on its relatively low EPSS score of 0.00083. Organizations should monitor for exploit development while prioritizing more critical vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.37.3CPE matchmatch criteria
cpe:2.3:a:microsoft:github_copilot_chat:*:*:*:*:*:visual_studio_code:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
50.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0074 is in the 62nd percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio Code CoPilot Chat ExtensionFixed in: 0.37.3
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-23653Important

GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Apr 14, 2026

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2026-23653
Vendor Advisory