CVE-2026-70335
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.42%
- CWE
- CWE-78
- Published
- 2026-08-11
- Last modified
- 2026-09-09
Affected products
- Microsoft Visual Studio Code
Weakness type
Related vulnerabilities
- CVE-2026-79641 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87088 — Tanium addressed an unauthorized code execution vulnerability in Enforce.
- CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
- CVE-2026-82004 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
- CVE-2026-81349 — Azure HDInsight Ambari Elevation of Privilege Vulnerability
- CVE-2026-86733 — Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore
- CVE-2026-61517 — Netis NX10 OS Command Injection via Ping Diagnostic Handler
- CVE-2026-71376 — OS Command Injection Vulnerability in Cosminexus Component Container