File Access Vulnerability in GitHub Copilot by Microsoft
CVE-2025-66389
7.5HIGH
What is CVE-2025-66389?
In GitHub Copilot version 1.372.0, a security flaw allows unauthorized filesystem access beyond the designated workspace folder via a file-handler URI parameter in the fetch_webpage tool. This could lead to potential exfiltration of sensitive information due to indirect prompt injection, posing a risk to users' data integrity.