Api.Msrc.Microsoft
Command Injection Vulnerability in GitHub Copilot and Windows Notepad
First seen 12 Feb 2026, 21:16 UTC
•
•13.6
Export
Article Content
Browse articles
A command injection vulnerability has been identified in GitHub Copilot, Visual Studio, and the Windows Notepad app, allowing unauthorized attackers to execute code over a network. The issue arises from improper neutralization of special elements used in commands. A proof of concept for CVE-2026-20841 was made public shortly after its publication.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-10
CVE-2026-20841 published
2026-02-10
CVE-2026 published for GitHub Copilot and Visual Studio
2026-02-11
First public PoC for CVE-2026-20841 released
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows