Skip to main content

Vendor/product archive

microsoft / github_copilot CVEs

Beta · best-effort

4 CVEs tagged to microsoft / github_copilot0 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-50510

Published Jul 14, 2026

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2025-66389

Published Jun 22, 2026

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-21516

Published Feb 10, 2026

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-64671

Published Dec 9, 2025

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

CVSS 8.4 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1