SB2025111203 - Improper Validation of Generative AI Output in Microsoft Visual Studio Code and GitHub Copilot
Published: November 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Validation of Generative AI Output (CVE-ID: CVE-2025-62453)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to improper validation of generative ai output in GitHub Copilot and Visual Studio Code. A local user can bypass Visual Studio Code sensitive file protections.
Remediation
Install update from vendor's website.