CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:github_copilot:1.372.0:*:*:*:*:visual_studio_code:*:*

History

30 Jun 2026, 00:05

Type Values Removed Values Added
First Time Microsoft github Copilot
Microsoft
References () https://blindcyber.com/2025/10/28/copilot-fun/ - () https://blindcyber.com/2025/10/28/copilot-fun/ - Exploit, Third Party Advisory
References () https://github.com/microsoft/vscode-copilot-chat/ - () https://github.com/microsoft/vscode-copilot-chat/ - Product
References () https://github.com/microsoft/vscode/blob/03baef1008086ed4960042fa463e570072173bb5/src/vs/workbench/contrib/chat/electron-browser/tools/fetchPageTool.ts#L152 - () https://github.com/microsoft/vscode/blob/03baef1008086ed4960042fa463e570072173bb5/src/vs/workbench/contrib/chat/electron-browser/tools/fetchPageTool.ts#L152 - Product
CPE cpe:2.3:a:microsoft:github_copilot:1.372.0:*:*:*:*:visual_studio_code:*:*

22 Jun 2026, 18:16

Type Values Removed Values Added
CWE CWE-552
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

22 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 14:16

Updated : 2026-06-30 00:05


NVD link : CVE-2025-66389

Mitre link : CVE-2025-66389

CVE.ORG link : CVE-2025-66389


JSON object : View

Products Affected

microsoft

  • github_copilot
CWE
CWE-552

Files or Directories Accessible to External Parties