Arbitrary Code Execution Vulnerability in GitHub Copilot CLI
CVE-2026-29783
7.5HIGH
What is CVE-2026-29783?
The GitHub Copilot CLI contains a vulnerability that allows arbitrary code execution through crafted bash parameter expansion patterns in versions up to and including 0.0.422. This issue arises from the CLI's shell safety assessment mechanism, which wrongly classifies certain commands as read-only. Attackers can exploit this vulnerability through prompt injection via manipulated repository files, malicious MCP server responses, or crafted user instructions, enabling them to execute hidden commands that can modify files or exfiltrate sensitive data. This vulnerability was addressed in version 0.0.423.
Affected Version(s)
copilot-cli <= 0.0.422