Path Traversal Vulnerability in GitHub Copilot and Visual Studio Code
CVE-2026-45482

8.4HIGH

What is CVE-2026-45482?

A path traversal vulnerability has been identified in GitHub Copilot and Visual Studio Code, allowing an unauthorized attacker to bypass local security mechanisms. This issue arises from improper limitation of pathname access to restricted directories, potentially compromising local security controls and exposing sensitive data.

Affected Version(s)

Microsoft Visual Studio Code CoPilot Chat Extension 0.27.0 < 1.123.2

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.