Path Traversal Vulnerability in GitHub Copilot and Visual Studio Code
CVE-2026-45482
8.4HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-45482?
A path traversal vulnerability has been identified in GitHub Copilot and Visual Studio Code, allowing an unauthorized attacker to bypass local security mechanisms. This issue arises from improper limitation of pathname access to restricted directories, potentially compromising local security controls and exposing sensitive data.
Affected Version(s)
Microsoft Visual Studio Code CoPilot Chat Extension 0.27.0 < 1.123.2