GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
References
Configurations
History
30 Jun 2026, 00:05
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Microsoft github Copilot
Microsoft |
|
| References | () https://blindcyber.com/2025/10/28/copilot-fun/ - Exploit, Third Party Advisory | |
| References | () https://github.com/microsoft/vscode-copilot-chat/ - Product | |
| References | () https://github.com/microsoft/vscode/blob/03baef1008086ed4960042fa463e570072173bb5/src/vs/workbench/contrib/chat/electron-browser/tools/fetchPageTool.ts#L152 - Product | |
| CPE | cpe:2.3:a:microsoft:github_copilot:1.372.0:*:*:*:*:visual_studio_code:*:* |
22 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-552 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
22 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 14:16
Updated : 2026-06-30 00:05
NVD link : CVE-2025-66389
Mitre link : CVE-2025-66389
CVE.ORG link : CVE-2025-66389
JSON object : View
Products Affected
microsoft
- github_copilot
CWE
CWE-552
Files or Directories Accessible to External Parties
