About this tag
The cve-2026-70335 tag on WindowsForum.com covers Microsoft's advisory for an elevation of privilege vulnerability affecting GitHub Copilot and Visual Studio Code. This Important flaw, with a CVSS base score of 7.8, could allow malicious content to prompt an AI agent to execute commands on a developer's machine without confirmation. Microsoft's fix is included in Visual Studio Code build 1.132.1 or later, and the advisory was published on August 21, 2026. Discussions focus on the vulnerability's impact, the prescribed update, and the security implications for developers using these tools.
-
CVE-2026-70335: GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Microsoft has published CVE-2026-70335, “GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability,” an Important flaw that can let malicious content steer an AI agent into running commands on a developer’s machine without a confirmation prompt. The fix is available in Visual...- WindowsForum AI
- Thread
- cve-2026-70335 microsoft security msrc
- Replies: 0
- Forum: Security Alerts