
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47282 is an insufficiently protected credentials vulnerability in GitHub Copilot and Visual Studio Code that allows an unauthorized network attacker to disclose sensitive authentication information. It was published on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release, which addressed a record 570 vulnerabilities. Affected versions include Visual Studio Code from 1.0.0 up to (excluding) 1.128.1; GitHub Copilot is also listed as affected. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (MSRC Advisory).
The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-522 (Insufficiently Protected Credentials), indicating that authentication credentials or tokens used by GitHub Copilot and/or Visual Studio Code are transmitted or stored without adequate protection. An unauthenticated network attacker can exploit this flaw to intercept or access these credentials, but user interaction is required for exploitation (e.g., a victim must perform some action that triggers the credential exposure). The attack vector is network-based with low complexity, and no privileges are required on the attacker's side (MSRC Advisory). No public proof-of-concept or detailed technical write-up has been identified at this time.
Successful exploitation results in a high confidentiality impact — specifically, the disclosure of authentication credentials or tokens associated with GitHub Copilot and Visual Studio Code over the network. There is no integrity or availability impact. Exposed credentials could potentially be reused by an attacker to access GitHub services, repositories, or Copilot-enabled resources on behalf of the victim, creating downstream risk of unauthorized code access or data exfiltration (MSRC Advisory).
Microsoft has released a patch addressing this vulnerability; users should update Visual Studio Code to version 1.128.1 or later. After patching, administrators and affected users should review any credentials or tokens that may have been exposed and revoke or rotate them as a precaution. The patch is available through the Microsoft Security Response Center and standard VS Code update mechanisms (MSRC Advisory).
CVE-2026-47282 was covered as part of broader reporting on Microsoft's July 2026 Patch Tuesday, which was notable for addressing a record 570 vulnerabilities including three zero-days. Coverage appeared in BleepingComputer, Qualys, Rapid7, Lansweeper, and SANS ISC, though this specific CVE did not receive significant individual attention given its medium severity and lack of active exploitation (BleepingComputer, Qualys Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."