Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GitHub Copilot 1.372.0 Filesystem Access Outside Workspace via File-Handler URI |
Mon, 22 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Filesystem Exfiltration via Unauthorized File-Handler URI in GitHub Copilot | |
| Weaknesses | CWE-200 CWE-284 |
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-552 | |
| Metrics |
cvssV3_1
|
Mon, 22 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft copilot |
|
| Vendors & Products |
Microsoft
Microsoft copilot |
Mon, 22 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Filesystem Exfiltration via Unauthorized File-Handler URI in GitHub Copilot | |
| Weaknesses | CWE-200 CWE-284 |
Mon, 22 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-22T16:02:08.057Z
Reserved: 2025-11-28T00:00:00.000Z
Link: CVE-2025-66389
Updated: 2026-06-22T16:02:02.785Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T19:30:06Z