Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:visual_studio_code_copilot_chat_extension:*:*:*:*:*:*:*:* |
Fri, 14 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft github Copilot Chat
|
|
| CPEs | cpe:2.3:a:microsoft:github_copilot_chat:*:*:*:*:*:visual_studio_code:*:* | |
| Vendors & Products |
Microsoft github Copilot Chat
|
Wed, 12 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft visual Studio Microsoft visual Studio Code Copilot Chat Extension |
|
| Vendors & Products |
Microsoft
Microsoft visual Studio Microsoft visual Studio Code Copilot Chat Extension |
Tue, 11 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | |
| Title | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability | |
| Weaknesses | CWE-20 CWE-77 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-26T16:57:16.098Z
Reserved: 2025-10-08T20:10:09.349Z
Link: CVE-2025-62222
Updated: 2025-12-11T15:14:59.260Z
Status : Analyzed
Published: 2025-11-11T18:15:49.887
Modified: 2025-11-14T15:47:58.830
Link: CVE-2025-62222
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:36:33Z