
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70335 is an OS command injection vulnerability (CWE-78) affecting GitHub Copilot and Visual Studio Code that allows an unauthorized attacker to elevate privileges locally. The vulnerability was disclosed on August 11, 2026, as part of Microsoft's August 2026 Patch Tuesday release. Visual Studio Code versions prior to 1.132.1 are confirmed affected. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the affected software constructs OS commands using externally-influenced input without properly sanitizing special characters or delimiters. The attack vector is local, requires no prior privileges, but does require user interaction to trigger — consistent with a scenario where a malicious project, file, or Copilot-generated content causes the application to execute attacker-controlled OS commands. The scope is unchanged, indicating the impact is confined to the vulnerable component's security context. No public proof-of-concept or detailed technical write-up has been identified at this time (MSRC Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary OS commands with elevated privileges on the local system running Visual Studio Code or GitHub Copilot. The CVSS metrics indicate high impact across confidentiality, integrity, and availability — meaning an attacker could access sensitive data, modify system files, or disrupt the availability of the affected system. Given that VS Code is widely used by developers with access to source code, credentials, and cloud environment configurations, exploitation could facilitate further lateral movement or credential theft within a development environment (MSRC Advisory, GitHub Advisory).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.476%, placing it in the 38th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported (MSRC Advisory, GitHub Advisory).
Microsoft has released a patch addressing this vulnerability in Visual Studio Code version 1.132.1 and later. Users should update VS Code to version 1.132.1 or higher immediately via the built-in update mechanism or by downloading from the official Microsoft website. GitHub Copilot should also be updated to the latest patched version. As a temporary workaround if immediate patching is not feasible, organizations may consider disabling or restricting the GitHub Copilot integration within VS Code until the update can be applied (MSRC Advisory, GitHub Advisory).
CVE-2026-70335 was covered as part of broader reporting on Microsoft's August 2026 Patch Tuesday, which addressed approximately 400 vulnerabilities including three zero-days. Security outlets including BleepingComputer, CyberSecurityNews, Rapid7, and Cisco Talos covered the August 2026 Patch Tuesday release, though CVE-2026-70335 was not highlighted as a top-priority item given the absence of active exploitation. The SANS Internet Storm Center and Kaspersky also noted the vulnerability in their Patch Tuesday summaries (BleepingComputer, Rapid7, Talos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."