VYPR

Copilot

by GitHub

CVEs (12)

  • CVE-2026-21518HigFeb 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-21516HigFeb 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

  • CVE-2026-21256HigFeb 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.

  • CVE-2026-21257HigFeb 10, 2026
    risk 0.52cvss 8.0epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-64660HigNov 20, 2025
    risk 0.52cvss 8.0epss 0.01

    Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

  • CVE-2026-70335HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-53773HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2025-66389HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.01

    GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

  • CVE-2026-23653MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

  • CVE-2025-62453MedNov 11, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-50510HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

  • CVE-2026-47282MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.