7.8
CVE-2026-50510
- EPSS 0.23%
- Veröffentlicht 14.07.2026 17:08:02
- Zuletzt bearbeitet 22.07.2026 16:24:29
- Erkennungen
GitHub Copilot Remote Code Execution Vulnerability
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Github Copilot SwPlatform jetbrains Version < 1.13.0-251
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-641 Improper Restriction of Names for Files and Other Resources
The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50510