CVE-2026-50510
Published Jul 14, 2026Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
- evidence mentions
- 4
- Buzz score
- 29.1
Vendor/product archive
4 CVEs tagged to microsoft / github_copilot — 0 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration co…
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.