CVE-2025-66389
EUVD-2025-21029822.06.2026, 14:16
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | github_copilot | 1.372.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration