Ostorlab[verified]@OstorlabSecPatch
GitHub Copilot VS Code extension is vulnerable to OS command injection (CVE‑2026‑21518). A public PoC exists, but no active exploitation has been reported; patches are available and should be applied immediately.
Hüseyin Tıntaş@1337stifDisclosure
The user reports discovering a remote code execution vulnerability in VS Code (CVE-2026-21518) and links to the official Microsoft advisory; no exploit code or active exploitation is mentioned.
CVE@CVEnewGeneral
The CVE notes a command injection flaw in GitHub Copilot and Visual Studio Code but provides no PoC, exploit, or patch details.
SystemTek - Technology news website@SystemTek_UKDisclosure
A tweet announces a new remote code execution vulnerability (CVE-2026-21518) in Visual Studio Code's mcp.json, providing only a basic technical description without PoC, exploit code, evidence of active use, or patch information.