{
  "cve_id": "CVE-2026-21518",
  "description": "Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.",
  "severity": "medium",
  "cvss": {
    "score": 6.5,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
  },
  "cwes": [
    {
      "cwe_id": "CWE-77",
      "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')"
    }
  ],
  "published_at": "2026-02-10T00:00:00Z",
  "updated_at": "2026-02-20T00:00:00Z",
  "references": [
    "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518",
    "https://www.cve.org/CVERecord?id=CVE-2026-21518"
  ],
  "assigner": "Microsoft"
}
