Here's the full writeup of CVE-2025-53773 - Visual Studio & Copilot – Wormable Command Execution via Prompt Injection: https://www.persistent-security.net/post/part-iii-vscode-copilot-wormable-command-execution-via-prompt-injection
Patch now!
@marver@mastodon.social
Security Chief Rocka @ X41
Here's the full writeup of CVE-2025-53773 - Visual Studio & Copilot – Wormable Command Execution via Prompt Injection: https://www.persistent-security.net/post/part-iii-vscode-copilot-wormable-command-execution-via-prompt-injection
Patch now!
Looks like I've got some LLM-to-RCE CVE assigned by Microsoft for Visual Studio / Copilot: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53773
As often the exploitability is claimed to be not likely..We will fix that tomorrow in a blog post, stay tuned!
Elk is a nimble Mastodon web client. You can login to your Mastodon account and use it to interact with the fediverse.
Expect some bugs and missing features here and there. Elk is Open Source and we're actively improving it as a community project. Join us and let's build it together!
If you'd like to report a bug, help us testing, give feedback, or contribute, reach out to us on GitHub and get involved.
To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!