VendorsMicrosoftgithub_copilotall versions
Vulnerabilities

Microsoft GitHub Copilot

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-21516
GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
Published 2026-02-10 · Analyzed
8.8EPSS 0.008
CVE-2025-64671
GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
Published 2025-12-09 · Analyzed
8.4EPSS 0.004
CVE-2026-50510
GitHub Copilot Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.004
CVE-2025-66389
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Published 2026-06-22 · Analyzed
7.5EPSS 0.012