VYPR

Vscode

by Microsoft

Source repositories

CVEs (1)

  • CVE-2025-66389HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.01

    GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.