Arbitrary Code Execution Vulnerability in GitHub Copilot CLI
CVE-2026-29783

7.5HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
6 March 2026

What is CVE-2026-29783?

The GitHub Copilot CLI contains a vulnerability that allows arbitrary code execution through crafted bash parameter expansion patterns in versions up to and including 0.0.422. This issue arises from the CLI's shell safety assessment mechanism, which wrongly classifies certain commands as read-only. Attackers can exploit this vulnerability through prompt injection via manipulated repository files, malicious MCP server responses, or crafted user instructions, enabling them to execute hidden commands that can modify files or exfiltrate sensitive data. This vulnerability was addressed in version 0.0.423.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

copilot-cli <= 0.0.422

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.