CVE-2026-50519Disclosure(microsoft / github_copilot_chat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft github_copilot_chat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • github_copilot_chat
  • visual_studio_code

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
github_copilot_chatvisual_studio_code

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-19: 2Mentions · 2026-06-23: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-19: 2Technical Details · 2026-06-23: 106-1906-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure2
2026-06-231
Patch1
Full discourse3 posts
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🚨 #GüvenlikBülteni #SiberGüvenlik: GitHub Copilot Chat'te Veri Sızıntısı Riski (CVE-2026-50519) Merhaba #Brolyz GitHub Copilot Chat ve Visual Studio Code entegrasyonunda tespit edilen yeni bir güvenlik açığı, hassas bilgilerin yetkisiz şekilde açığa çıkmasına neden olabilecek bir risk oluşturuyor. 📌 Ne Oluyor? CVE-2026-50519 olarak takip edilen zafiyet, Copilot Chat'in bazı kaynakları güvensiz varsayılan ayarlarla başlatmasından kaynaklanıyor. Araştırmacılar, bu durumun belirli koşullarda bilgi ifşasına yol açabileceğini belirtiyor. ⚠️ Riskler Neler? • Hassas verilerin yetkisiz kişilere açığa çıkması • Güvenlik kontrollerinin kısmen atlatılması • Ağ üzerinden gerçekleştirilebilecek bilgi toplama girişimleri 🛡️ Alınabilecek Önlemler 1️⃣ GitHub Copilot Chat eklentisini en güncel sürüme yükseltin. 2️⃣ VS Code eklentilerinin güncelliğini düzenli olarak kontrol edin. 3️⃣ Yapay zeka araçlarıyla paylaşılan hassas verileri gözden geçirin. 4️⃣ Kurumsal ortamlarda erişim ve veri paylaşım politikalarını sıkılaştırın. 📊 Neden Önemli? Her ne kadar kritik seviyede bir RCE açığı olmasa da, yapay zeka destekli geliştirme araçlarının kurumsal ortamlarda yaygınlaşması nedeniyle veri sızıntısı riskleri giderek daha fazla önem kazanıyor. 🔚 Sonuç Copilot ve benzeri yapay zeka araçları geliştiricilere büyük kolaylık sağlıyor. Ancak güvenlik güncellemelerinin geciktirilmesi, hassas bilgilerin istemeden açığa çıkmasına neden olabilir.

    Post summary

    GitHub Copilot Chat has a CVE‑2026‑50519 vulnerability that can leak sensitive data; users are advised to update immediately to the latest version.

    0102080
    436 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50519 Information Disclosure in GitHub Copilot and Visual Studio Code via Insecure Default Initialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50519

    Post summary

    CVE-2026-50519 is identified as an information disclosure flaw in GitHub Copilot and Visual Studio Code caused by insecure default initialization. The text provides no evidence of exploits, active use, or remediation steps.

    0000061
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50519 Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-50519

    Post summary

    The post announces CVE-2026-50519, describing an insecure default initialization that allows unauthorized information disclosure in GitHub Copilot and VS Code, but does not provide any PoC, exploit, patch, or active exploitation details.

    00000233
    57.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftgithub_copilot_chat-visual_studio_code-
Appmicrosoftvisual_studio_code---

Explore more