CVE-2026-70335

CVE-2026-70335CVE-2026-70335

Description

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

Scoring

CVSS 7.8 ()
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Last modified2026-08-11
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.