CVE-2026-23653 is a command injection vulnerability in GitHub Copilot and Visual Studio Code that permits authorized users to execute arbitrary commands and potentially disclose sensitive information over a network. The flaw stems from improper neutralization of special elements in command processing, allowing an attacker to manipulate input and gain unauthorized data access. The vulnerability carries a MEDIUM severity rating (CVSS 5.7) with a network-based attack vector requiring low complexity and low privileges, though user interaction is necessary. The primary impact is confidentiality compromise, with no integrity or availability effects. The FAUCET Risk Score of 33.0/100 suggests moderate concern. This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation in the wild. It remains in an inactive status on relevant vulnerability tracking lists, and community attention appears limited based on its relatively low EPSS score of 0.00083. Organizations should monitor for exploit development while prioritizing more critical vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.37.3CPE matchmatch criteria | cpe:2.3:a:microsoft:github_copilot_chat:*:*:*:*:*:visual_studio_code:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.