Command Injection Vulnerability in GitHub Copilot by Microsoft
CVE-2025-64671
8.4HIGH
What is CVE-2025-64671?
A security flaw in GitHub Copilot permits unauthorized attackers to carry out command injection attacks. By exploiting improper neutralization of special elements, these attackers can execute arbitrary code on the affected system. This vulnerability poses a significant risk, and it is essential for users to apply available updates and implement appropriate security measures to mitigate potential exploits.
Affected Version(s)
GitHub Copilot Plugin for JetBrains IDEs Unknown 1.0.0 < 1.5.60-243