Command Injection Vulnerability in GitHub Copilot by Microsoft
CVE-2025-64671
8.4HIGH
What is CVE-2025-64671?
A security flaw in GitHub Copilot permits unauthorized attackers to carry out command injection attacks. By exploiting improper neutralization of special elements, these attackers can execute arbitrary code on the affected system. This vulnerability poses a significant risk, and it is essential for users to apply available updates and implement appropriate security measures to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitHub Copilot Plugin for JetBrains IDEs Unknown 1.0.0 < 1.5.60-243
News Articles
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- π°
First article discovered by theregister.com
Vulnerability published
Vulnerability Reserved