High
nvd
·
CVE-2026-33111
CVE-2026-33111: Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all
Published May 7, 2026
CVSS 7.5
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Affected AI Products
copilot