CVE-2026-21518Disclosure(microsoft / visual_studio_code)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft visual_studio_code systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • visual_studio_code

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
visual_studio_code

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-13: 1Mentions · 2026-02-21: 1Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-02-13: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-21: 1Technical Details · 2026-04-03: 102-1002-1302-2104-03
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-101
General1
2026-02-131
Patch1
2026-02-211
Disclosure1
2026-04-031
Disclosure1
Full discourse4 posts
  • Hüseyin Tıntaş@1337stif
    Disclosure

    I found RCE in VS Code CVE-2026-21518 https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21518 https://t.co/Cg2KTjYr7y

    Post summary

    The user reports discovering a remote code execution vulnerability in VS Code (CVE-2026-21518) and links to the official Microsoft advisory; no exploit code or active exploitation is mentioned.

    35067173.7K
    247 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2026-21518: GitHub Copilot VS Code Command Injection Vulnerability 🚨 A command injection flaw in GitHub Copilot for Visual Studio Code allows unauthenticated attackers to execute system commands via crafted network payloads. Public PoC available targeting developer environments. Risk Severity: Medium (CVSS 6.5, unauthenticated, high-value targets) Impact: Developer workstation compromise Source code theft Supply chain poisoning Cloud credential theft Enterprise lateral movement Root Cause: CWE-78 (OS Command Injection) – Improper neutralization of attacker-controlled network input before execution in VS Code extension host. Attackers can: Execute arbitrary system commands Steal API keys & cloud credentials Access proprietary source code Implant malicious commits Compromise CI/CD pipelines Are You Affected? Vulnerable: GitHub Copilot VS Code extension versions prior to security patch Remote VS Code Server deployments Network-exposed developer environments Fixed in: Latest GitHub Copilot extension release (February 2026 security fix) Immediate Action Required: Update/Patch: Update GitHub Copilot extension immediately Mitigation (if patching is delayed): Temporarily disable Copilot Restrict network access to VS Code instances Enforce VPN-only developer access Implement IP allowlisting Audit & Monitor: Hunt for VS Code spawning shell processes Monitor child processes from Code.exe Review EDR logs for command injection indicators Inspect recent source code commits for backdoors Compromising developer tooling enables full supply-chain attacks — patch immediately and assume breach risk. 🔐 #ostorlabCVE

    Post summary

    GitHub Copilot VS Code extension is vulnerable to OS command injection (CVE‑2026‑21518). A public PoC exists, but no active exploitation has been reported; patches are available and should be applied immediately.

    00010114
    581 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-21518 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass… https://www.cve.org/CVERecord?id=CVE-2026-21518

    Post summary

    The CVE notes a command injection flaw in GitHub Copilot and Visual Studio Code but provides no PoC, exploit, or patch details.

    00010450
    56.5K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Microsoft Visual Studio Code mcp.json Command Injection Remote Code Execution Vulnerability (CVE-2026-21518) #CVE202621518 #CyberSecurity #Microsoft #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/?p=48983 https://t.co/IN5QxJtRRF

    Post summary

    A tweet announces a new remote code execution vulnerability (CVE-2026-21518) in Visual Studio Code's mcp.json, providing only a basic technical description without PoC, exploit code, evidence of active use, or patch information.

    0000067
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftvisual_studio_code---

Explore more