Junglewise Threat Intelligence

CVE-2026-81381: Microsoft Visual Studio Code credential exposure in GitHub Copilot

CVE-2026-81381 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Visual Studio Code and GitHub Copilot store authentication credentials in a way that does not adequately protect them from unauthorized access. An attacker with network access could potentially intercept or extract these credentials, gaining unauthorized access to user accounts and sensitive services.

Technical details

The vulnerability stems from insufficiently protected credential storage in Visual Studio Code and GitHub Copilot. Sensitive authentication tokens and credentials are not properly encrypted or secured, allowing an attacker with network access to disclose this information. The attack does not require prior authentication or special user interaction beyond standard use of the affected tools. Successful exploitation could allow an attacker to impersonate legitimate users and access their accounts and integrated services. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Visual Studio Code <UNKNOWN>
  • GitHub Copilot <UNKNOWN>

Timeline

  • 2026-09-08: disclosed: Public disclosure via NVD

References

Related threats