High
CVSS: 8.0
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
High
CVSS: 8.0
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Medium
CVSS: 5.0
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
High
CVSS: 8.8
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
High
CVSS: 7.1
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Medium
CVSS: 6.8
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.3
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.3
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
High
CVSS: 7.3
Visual Studio Code Elevation of Privilege Vulnerability