Arbitrary Code Execution Vulnerability in GitHub Copilot CLI
CVE-2026-29783
What is CVE-2026-29783?
The GitHub Copilot CLI contains a vulnerability that allows arbitrary code execution through crafted bash parameter expansion patterns in versions up to and including 0.0.422. This issue arises from the CLI's shell safety assessment mechanism, which wrongly classifies certain commands as read-only. Attackers can exploit this vulnerability through prompt injection via manipulated repository files, malicious MCP server responses, or crafted user instructions, enabling them to execute hidden commands that can modify files or exfiltrate sensitive data. This vulnerability was addressed in version 0.0.423.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
copilot-cli <= 0.0.422
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved