VYPR

Github Copilot Chat

by Microsoft

CVEs (6)

  • CVE-2025-62222HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65675HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-62449MedNov 11, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-50519MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23653MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

  • CVE-2026-50510HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.