CVE-2026-41109
visual_studio_code: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CVE-2026-41109)
Affected
- microsoft/visual_studio_code
lt *..1.119.1
Description
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.119.1fixed from 1.119.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-74Class
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-10 18:17 UTC· secure@microsoft.com
- Affected: Visual Studio Code → Visual Studio Code
- CVE Modified2026-08-10 16:19 UTC· secure@microsoft.com
- Affected: Visual Studio Code → Visual Studio Code