Description
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Weaknesses
- — n/a
Affected products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
References
Generated from the official CVE List on 22 Jun 2026 14:43 UTC.