
AIコーディング、便利すぎて怖い。 GitHub Copilot Plugin 1.372.0、 プロンプトインジェクションが 刺さると、ワークスペース外の ファイルに無断アクセスされる。 CVSS v3スコアは7.5(重要)。 CVE-2025-66389。 AIアシストが裏で ファイルシステムを歩き回る、 そういうリスクがもう現実にある。 バージョン確認と ベンダー対応の確認を。
Post summary
The post announces CVE-2025-66389 affecting GitHub Copilot Plugin 1.372.0, describing prompt injection that can lead to unauthorized file access with a CVSS score of 7.5.

