Skip to content

Sensitive file editing guard bypass #276771

@connor4312

Description

@connor4312

VS Code - Sensitive file editing guard bypass

A remote code execution vulnerability exists in VS Code Copilot Chat 0.32.4 and earlier versions where a prompt-injected agent mode chat could make edits to sensitive files such as .vscode/settings.json, bypassing the normal sensitivity check.

Patches

The fix is available starting with VS Code Copilot Chat 0.32.5. The fix mitigates this attack by validating paths provided to edit tools.

Workarounds

Avoid including untrusted input or context in your agent loop.

References

Metadata

Metadata

Assignees

Labels

candidateIssue identified as probable candidate for fixing in the next releasechatsecurityverifiedVerification succeeded

Type

No type
No fields configured for issues without a type.

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions