High severity8.4NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2025-64671
CVE-2025-64671
Description
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.
Affected products
3- cpe:2.3:a:microsoft:github_copilot:*:*:*:*:*:jetbrains:*:*Range: <1.5.60-243
- Microsoft/GitHub Copilot Plugin for JetBrains IDEsv5Range: 1.0.0
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-64671nvdVendor Advisory
News mentions
0No linked articles in our index yet.