Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Github Copilot
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-50510 1 Microsoft 1 Github Copilot 2026-07-22 N/A 7.8 HIGH
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
CVE-2025-66389 1 Microsoft 1 Github Copilot 2026-06-30 N/A 7.5 HIGH
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
CVE-2026-21516 1 Microsoft 1 Github Copilot 2026-06-17 N/A 8.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
CVE-2025-64671 1 Microsoft 1 Github Copilot 2026-06-17 N/A 8.4 HIGH
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.