PT-2025-32853 · Microsoft+1 · Visual Studio+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitHub Copilot (affected versions not specified)
Visual Studio 2022 versions prior to 17.14.12
Description
Improper neutralization of special elements used in a command leads to a command injection issue in GitHub Copilot and Visual Studio, allowing an unauthorized attacker to execute code locally. This can be achieved through prompt injection, where an attacker hides malicious instructions within a repository comment, README, or PR description. The AI assistant may be tricked into modifying the
.vscode/settings.json file to enable an auto-approve mode, which allows the agent to execute arbitrary bash commands in the terminal without human confirmation.Recommendations
Update Visual Studio 2022 to version 17.14.12.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for GitHub Copilot.
Exploit
Fix
LPE
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github Copilot
Visual Studio