Command Injection Vulnerability in GitHub Copilot by Microsoft
CVE-2025-64671

8.4HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 December 2025

Badges

๐Ÿ“ฐ News Worthy

What is CVE-2025-64671?

A security flaw in GitHub Copilot permits unauthorized attackers to carry out command injection attacks. By exploiting improper neutralization of special elements, these attackers can execute arbitrary code on the affected system. This vulnerability poses a significant risk, and it is essential for users to apply available updates and implement appropriate security measures to mitigate potential exploits.

Affected Version(s)

GitHub Copilot Plugin for JetBrains IDEs Unknown 1.0.0 < 1.5.60-243

News Articles

Patch Tuesday: Microsoft EoP, NotePad++, Ivanti, Fortinet

Happy December Patch Tuesday to all who celebrate. This month's patch party includes one Microsoft flaw under exploitation, plus two others listed as publicly known โ€“ but just 57 CVEs in total from...

13 hours ago

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ“ฐ

    First article discovered by theregister.com

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64671 : Command Injection Vulnerability in GitHub Copilot by Microsoft