---
id: CVE-2026-50519
title: >-
  Initialization of a resource with an insecure default in GitHub Copilot and
  Visual Studio Code allows an unauthorized attacker to disclose information
  over a network.
summary: >-
  Initialization of a resource with an insecure default in GitHub Copilot and
  Visual Studio Code allows an unauthorized attacker to disclose information
  over a network.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-1188
vendor: microsoft
product: github_copilot_chat
affected:
  - github_copilot_chat < 1.123.2
patched:
  - github_copilot_chat 1.123.2
published: '2026-06-19'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50519'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50519'
    label: secure@microsoft.com
tags:
  - nvd
  - cve.org
epss: 0.00922
epssPercentile: 0.58685
ingestedAt: '2026-06-29T15:48:27.763Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-22T17:42:31.922172Z'
---

## Overview

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

## Affected

- `github_copilot_chat < 1.123.2`

## Remediation

Upgrade past the affected range:

- `github_copilot_chat 1.123.2`
