Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
How could an attacker exploit this vulnerability? An attacker could embed malicious instructions in content that the AI agent processes, such as a web page, a repository file, or a tool response. When a user runs the agent against that content, the injected instructions could cause the agent to run commands on the user's machine without prompting for confirmation. Successful exploitation could allow the attacker to execute code in the context of the signed-in user. User interaction is required and the attack is carried out locally; no authentication is required for the attacker to supply the content.
<a href="https://www.linkedin.com/in/tarek-nakkouch/">Tarek Nakkouch</a>