Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
Loading...
Loading...
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2026-02-10. NVD baseline CVSS 8.8; sources differ by 0.0.
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
February 10, 2026
February 11, 2026
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-21516
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
msrc
CWE-77