CVE-2025-53773Disclosure(microsoft / visual_studio_2022)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft visual_studio_2022 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • visual_studio_2022

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 23 mentions across 19 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 20 signals
  • Disclosure: 9 classified signals
  • General: 6 classified signals
  • Peaked 14d ago at 3 mentions (2026-03-14); latest day: 1
  • 23 total mentions across 19 days

Affected systems

Vendors
Products
visual_studio_2022

Deep dive

Activity timeline23 mentions / 19d
01223Mentions · 2026-02-03: 1Mentions · 2026-02-28: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-14: 3Mentions · 2026-03-23: 2Mentions · 2026-04-06: 1Mentions · 2026-05-06: 2Mentions · 2026-05-22: 1Mentions · 2026-05-26: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 1Mentions · 2026-06-08: 1Mentions · 2026-06-28: 1Mentions · 2026-07-08: 1Mentions · 2026-07-30: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-06-28: 1Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-06-04: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-14: 2Technical Details · 2026-03-23: 2Technical Details · 2026-04-06: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-22: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-30: 1Technical Details · 2026-09-17: 102-0302-2803-0603-1003-1403-2304-0605-0605-2205-2605-3106-0106-0306-0406-0806-2807-0807-3009-17
Signal classification5 categories
Disclosure
939.1%
General
626.1%
Active Exploitation
417.4%
Patch
313.0%
Exploit
14.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-281
Patch1
2026-03-061
Disclosure1
2026-03-101
Disclosure1
2026-03-143
Disclosure1General2
2026-03-232
Active Exploitation2
2026-04-061
Disclosure1
2026-05-062
Active Exploitation1Patch1
2026-05-221
Disclosure1
2026-05-261
Disclosure1
2026-05-311
General1
2026-06-011
General1
2026-06-031
General1
2026-06-041
Patch1
2026-06-081
Exploit1
2026-06-281
Disclosure1
2026-07-081
Active Exploitation1
2026-07-301
General1
2026-09-171
Disclosure1
Full discourse20 posts
  • Markus Vervier@marver
    General

    Sharing some personal experience with MSRC: First upfront disclaimer: I've not reported many vulnerabilities to them so far, but some high profile ones like CVE-2025-53773 and CVE-2020-16875. Mainly because I was never very active in Windows specific security research, only as a code reviewer for proprietary software. So I can't claim I'm an expert in dealing with MSRC. The few times I have dealt with them though showed one pattern: There was always a political and corporate communication angle to any conversation and interaction. and that was much stronger than with any other of the many corporations I had to deal with over the years. Where for other vendors the technical details and impact was always first, it felt like there was a filter in my interactions that delayed communication. I didn't even get an update for when something was fixed. On top of it it was never transparent who is actually looking at the vulnerabilities. In case of CVE-2020-16875 the bug was not patched correctly at least two times, despite me proposing a patch and offering help looking at theirs. I've met a few MSRC folks at conferences over the past last years and everyone was super nice and skilled! So what we can conclude: "A fish rots from the head down" Microsoft should just hand over the process to people who manage it well and own their mistakes as a corporation in a proper way. Others have successfully done it before!

    Post summary

    The user shares personal frustration with MSRC’s communication process, noting delayed responses and unpatched bugs, but offers no concrete technical or exploit details. The post reflects a general commentary on vendor handling rather than providing actionable vulnerability information.

    1705944.0K
    3.4K followersView on X
  • Abhishek Meena 🏵️@aacle_
    General

    One injection. One config write. Full RCE on the developer's machine. That's CVE-2025-53773, and it's the pattern behind every MCP escalation chain. Part 4 breaks it down hop by hop. https://medium.com/@Aacle/3-hops-to-rce-mcp-security-part-4-c1e6498c7b4c?sk=2a2e4db4ed9c991d4896470fa64e12a5

    Post summary

    The post references CVE-2025-53773, outlining an injection and config write that culminate in full RCE on a developer machine, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    1301092.0K
    49.5K followersView on X
  • Karthikeyan TS@keyashqa
    Exploit

    An Important message for all Vibe Coders. Even downloading a repo can get you hacked...📌📌 CVE-2025-53773 is a wild reminder of how easily a prompt injection can escalate into full Remote Code Execution (RCE) on your machine. The exploit chain is terrifyingly simple: 1. The Poisoned Context: An attacker hides a malicious prompt inside a repo comment or README. 2. The Privilege Escalation: Copilot reads it and is tricked into silently modifying .vscode/settings.json to enable YOLO mode ("http://chat.tools.autoApprove": true). 3. The Payload: With human confirmation disabled, the agent immediately opens a terminal and executes arbitrary bash commands on behalf of the attacker. No malicious links clicked. You just opened a workspace, and your assistant compromised your environment. The Golden Rule for building with autonomous agents: Never give an agent write access to the configuration files that govern its own boundaries. Stay secure while you ship. 🛠️ If you are shipping, then we should connect...

    Post summary

    The post outlines a straightforward prompt injection exploit chain that leads to remote code execution for CVE-2025-53773, but it provides no PoC code, patch information, or evidence of in‑the‑wild activity.

    1001095
    23 followersView on X
  • Veriprajna@veriprajna
    Disclosure

    Exhibit A: GitHub Copilot RCE (CVE-2025-53773). A hidden prompt in a README could hijack a developer's entire workstation. A linguistic input escalated to full system compromise. Read that again.

    Post summary

    The tweet announces a new RCE vulnerability in GitHub Copilot (CVE-2025-53773) and hints at how a hidden prompt could lead to full system compromise, but it does not provide a PoC, exploit code, mitigation, or evidence of active exploitation.

    20000141
    3 followersView on X
  • XHack@xhackio
    Patch

    AI Exploitation Techniques AI exploitation techniques have evolved from theoretical research to weaponized attacks against production systems. GitHub Copilot suffered CVE-2025-53773 (CVSS 9.6), enabling remote code execution through prompt injection. Microsoft patched a zero-click data exfiltration flaw (EchoLeak) in Copilot. PoisonedRAG achieved 90% attack success rates with just five injected documents. https://xhack.io/blog/ai-exploitation-techniques-a-complete-guide #AI #LLM #AISecurity

    Post summary

    CVE-2025-53773 in GitHub Copilot enables remote code execution through prompt injection; Microsoft has patched the flaw, addressing a zero‑click data exfiltration issue (EchoLeak).

    10010211
    4 followersView on X
  • Akash Trehan@theakashtrehan
    Disclosure

    This is not theoretical. CVE-2025-53773 in GitHub Copilot and VS Code allowed an untrusted file with an embedded prompt injection to exploit the AI into enabling 'YOLO mode' and running unauthorized commands under user permissions. (10/n)

    Post summary

    The tweet discloses CVE-2025-53773 in GitHub Copilot and VS Code, explaining how prompt injection via an untrusted file can lead to unauthorized command execution. No PoC, exploit, patch, or active exploitation is mentioned.

    1000091
    366 followersView on X
  • Prakalp Choubey@ChoubeyPrakalp
    Disclosure

    🔓 GitHub Copilot RCE (CVE-2025-53773) — injection hidden in repo comments → arbitrary code execution on dev machines. 🔓 MCP RCE (CVE-2025-6514) — 9.6 severity, in infra used by hundreds of thousands of devs. https://botmonster.com/posts/ai-coding-agent-insider-threat-prompt-injection-mcp-exploits/

    Post summary

    Two high‑severity RCE vulnerabilities (CVE‑2025‑53773 and CVE‑2025‑6514) have been disclosed, with details on injection vectors and arbitrary code execution, but no evidence of active exploitation or patch availability.

    1000055
    16 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-53773 2 - CVE-2025-32711 3 - CVE-2022-0492 4 - CVE-2024-21182 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A straightforward list of trending CVEs without further technical or contextual information.

    00010124
    1.7K followersView on X
  • ⚡🛡️ Evan Pappas@Hevalon
    Disclosure

    The inverse case: ZombAIs (CVE-2025-53773). Prompt injection -> Copilot edits .vscode/settings.json to enable autoApprove -> terminal commands run unconfirmed -> RCE. Three boundaries failed at once. Most production systems have none of the three.

    Post summary

    The post outlines a newly disclosed CVE-2025-53773, detailing how prompt injection via Copilot leads to an RCE, without providing a PoC, exploit, or patch.

    10000596
    1.4K followersView on X
  • ttfr ai トレンド@neural_nw_ai
    Patch

    GitHub CopilotにRCE脆弱性CVE-2025-53773(パッチ済)。悪意あるPRコメントのプロンプトインジェクションでVSCode設定を書き換え、マルウェア実行・リポジトリ全体に伝播も。AIコーディングツールの攻撃面は本当に深刻🔒 https://ai-trend-watch.pages.dev/2026/04/20/github-copilot-cve-2025-53773/ #セキュリティ #GitHubCopilot #AIセキュリティ

    Post summary

    The post reports that GitHub Copilot had a remote‑code‑execution flaw (CVE‑2025‑53773) which was already patched, explaining how malicious PR comments could rewrite VSCode settings to run malware, but no PoC or exploit was disclosed.

    000101.1K
    12 followersView on X
  • Adam4real@Adam4real4
    Active Exploitation

    這不是理論,是已經發生的事: - CVE-2025-6514:MCP OAuth RCE,43 萬裝機量 - CVE-2025-53773:Copilot 被注入開啟「YOLO 模式」,自動核准所有操作,可蠕蟲傳播 - postmark-mcp:npm 惡意套件,靜默轉發所有信件給攻擊者 - SANDWORM:19 個釣魚套件偷 SSH key 和 AWS 憑證

    Post summary

    The post reports that several recent CVEs are already being exploited in the wild, involving an OAuth RCE, an automated approval injection in Copilot, a malicious npm package that silently forwards mail, and a phishing tool that steals SSH keys and AWS credentials.

    1000057
    3 followersView on X
  • Adam4real@Adam4real4
    Active Exploitation

    Real incidents, not theory: - CVE-2025-6514: MCP OAuth proxy RCE, 437K+ installs - CVE-2025-53773: Copilot "YOLO mode" — wormable RCE - postmark-mcp: malicious npm package forwarded all emails to attacker - SANDWORM: 19 typosquatted packages stealing SSH keys

    Post summary

    The text reports real‐world exploitation of CVE‑2025‑6514 and CVE‑2025‑53773 via remote code execution, noting widespread installation counts and wormable behavior.

    1000041
    3 followersView on X
  • Ali Noori | Tusiro@omniuxai
    Disclosure

    This isn't theory. Look at CVE-2025-53773. A prompt injection can trigger "YOLO Mode" in your assistant, allowing Remote Code Execution (RCE) directly on your machine. And CVE-2026-2256 just proved that even MS-Agent isn't safe from logic-bypass attacks. https://t.co/nkwi3gmUN3

    Post summary

    The tweet announces that CVE‑2025‑53773 permits remote code execution via prompt injection, and CVE‑2026‑2256 reveals a logic‑bypass on MS‑Agent; no exploit code or active exploitation is reported.

    10000178
    2 followersView on X
  • Can Artuc@canartuc
    General

    4/ The risk: Autopilot with auto-approved tool calls means arbitrary code execution on your dev machine. SSH keys, cloud credentials, API tokens, all accessible. Prompt injection is a documented attack vector (CVE-2025-53773). The attack surface just expanded to every IDE session.

    Post summary

    The post warns that Autopilot’s auto‑approved tool calls can cause arbitrary code execution and expose SSH keys, cloud credentials, and API tokens, highlighting prompt injection as the documented attack vector (CVE‑2025‑53773).

    10000160
    169 followersView on X
  • Yaniv Radunsky@hasamba
    General

    Sec-Context: comprehensive AI code anti-patterns for LLMs — breadth (~65K tokens) and depth (~100K tokens) references. Top risks: dependency squatting, XSS, hardcoded secrets. #XSS #LLM #CVE-2025-53773 https://github.com/Arcanum-Sec/sec-context

    Post summary

    The tweet merely references CVE-2025-53773 within a broader discussion of AI code anti-patterns, without providing any actionable or detailed vulnerability information.

    00010171
    688 followersView on X
  • XHack@xhackio
    Disclosure

    EchoLeak (CVE-2025-32711) demonstrated zero-click data exfiltration from Microsoft 365 Copilot. GitHub Copilot’s CVE-2025-53773 (CVSS 9.6) enabled remote code execution through injected code comments. Security researcher Johann Rehberger spent $500 testing Devin AI and found it completely defenseless, allowing attackers to expose ports, leak tokens, and install malware through crafted prompts. The UK’s National Cyber Security Centre warned in December 2025 that prompt injection may never be fully mitigated with current architectures. This is XHack’s breakdown of how prompt injection works, every major attack variant, documented real-world incidents, and the defense strategies we implement and test across client engagements Read More at: https://xhack.io/blog/prompt-injection-attacks-risks-for-chatbots

    Post summary

    The passage discloses two severe CVEs affecting Microsoft 365 Copilot and GitHub Copilot, describing their exploitability and associated risks without offering PoC evidence or mitigation advice.

    00010133
    3 followersView on X
  • wangwang@xiyouwukong
    Disclosure

    ⚠️ CRITICAL: GitHub Copilot has a Remote Code Execution vulnerability (CVE-2025-53773) Prompt injection can lead to RCE. If you're using Copilot in production, review your security posture NOW. #GitHub #Security #DevSecOps

    Post summary

    A critical Remote Code Execution vulnerability (CVE‑2025‑53773) in GitHub Copilot has been disclosed, warning that prompt injection can lead to RCE and urging users to review their security posture.

    1000081
    49 followersView on X
  • Justin Kwon@ju571nK
    Active Exploitation

    プロンプトインジェクション、2026年も OWASP の LLM 脅威1位のまま。PR の説明文に隠したインジェクションで Copilot が RCE された CVE-2025-53773(9.6)とか、365 Copilot のゼロクリック情報漏洩 EchoLeak とか。コーディングエージェントに権限を渡しすぎると CI/CD がそのまま攻撃面になる。ツールごとの最小権限、ちゃんとやろう。 #セキュリティ #AIセキュリティ #DevSecOps https://www.securance.com/blog/prompt-injection-the-owasp-1-ai-threat-in-2026/

    Post summary

    The post reports that Copilot was successfully RCE'ed via a prompt‑injection flaw (CVE‑2025‑53773) and highlights the ongoing AI threat landscape.

    0000083
    6 followersView on X
  • ttfr ai トレンド@neural_nw_ai
    Patch

    GitHub CopilotのPRコメントに隠れたプロンプトでRCE(CVE-2025-53773、CVSS 9.6)。PRの説明文がシェルコマンドになる時代に。AIコードレビューを使っているチームは今すぐパッチ確認を https://ai-trend-watch.pages.dev/2026/04/20/github-copilot-cve-2025-53773/ #GitHubCopilot #AIセキュリティ #脆弱性

    Post summary

    The post highlights a high‑severity RCE vulnerability (CVE‑2025‑53773) in GitHub Copilot’s PR prompt handling and urges teams to verify patches immediately.

    00000135
    18 followersView on X
  • Justin Kwon@ju571nK
    General

    AIコーディングの最大リスク、プロンプトインジェクション🤖 OWASPが2026年No.1 AI脅威に。PR説明に隠した注入でCopilotのRCE(CVE-2025-53773, CVSS9.6)、ゼロクリック流出のEchoLeak、Cursorのコマンド実行欠陥…成功率は構成次第で50〜84%。AIエージェントの実行権限を最小化しましょう。 #セキュリティ #AIセキュリティ #LLM #DevSecOps https://www.securance.com/blog/prompt-injection-the-owasp-1-ai-threat-in-2026/

    Post summary

    The tweet cites OWASP’s 2026 AI threat list, highlighting prompt injection and a high‑CVSS RCE CVE‑2025‑53773, but it offers no exploit code, patch details, or evidence of active attacks.

    00000107
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftvisual_studio_2022---

Explore more