Github Copilot
by Microsoft
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41109 | Hig | 0.57 | 8.8 | 0.01 | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-21516 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-64671 | Hig | 0.55 | 8.4 | 0.00 | Dec 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-66389 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2026 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. | ||
| CVE-2026-50519 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50510 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. |
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
- risk 0.55cvss 8.4epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.
- risk 0.49cvss 7.5epss 0.01
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
- risk 0.42cvss 6.5epss 0.01
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.