CVE-2026-50510
Published Jul 14, 2026Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
- evidence mentions
- 4
- Buzz score
- 29.1
CWE archive
16 CVEs tagged with CWE-641 — 0 Critical, 11 High, 5 Medium, 0 Low, 0 Unrated.
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as…
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface.…
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips th…
Microsoft Office OneNote Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that all…
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor c…
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sen…
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` UR…