CVE-2025-53773
HIGH 7.8EPSS 2.6%
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 2.57% chance of exploitation in the next 30 days, 84th percentile
- Published
- 2025-08-12
- Updated
- 2026-02-26
Proof-of-concept exploits (3)
- https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt…
- persistent-security/poc-ai-copilot-rce1★ · 2025-08-13
- heatonb1/AI-Red-Teaming-Guide-Fork