Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
Wed, 10 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability |
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Title | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | |
| First Time appeared |
Microsoft
Microsoft visual Studio Code Copilot Chat Extension |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:microsoft:visual_studio_code_copilot_chat_extension:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft visual Studio Code Copilot Chat Extension |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-06-26T19:41:33.828Z
Reserved: 2026-05-12T16:07:22.617Z
Link: CVE-2026-45482
Updated: 2026-06-10T10:19:50.160Z
Status : Awaiting Analysis
Published: 2026-06-09T17:17:22.587
Modified: 2026-06-09T19:32:51.440
Link: CVE-2026-45482
No data.
OpenCVE Enrichment
Updated: 2026-06-19T23:30:05Z