CVE-2025-66389Disclosure(microsoft / github_copilot)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • github_copilot

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
github_copilot

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1PoC Mentioned / Linked · 2026-06-30: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 106-3007-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-011
General1
Full discourse2 posts
  • くろん|情シスAIラボ@josys_AI_labo
    General

    AIコーディング、便利すぎて怖い。 GitHub Copilot Plugin 1.372.0、 プロンプトインジェクションが 刺さると、ワークスペース外の ファイルに無断アクセスされる。 CVSS v3スコアは7.5(重要)。 CVE-2025-66389。 AIアシストが裏で ファイルシステムを歩き回る、 そういうリスクがもう現実にある。 バージョン確認と ベンダー対応の確認を。

    Post summary

    The post announces CVE-2025-66389 affecting GitHub Copilot Plugin 1.372.0, describing prompt injection that can lead to unauthorized file access with a CVSS score of 7.5.

    10000100
    18 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 CRITICAL: CVE-2025-66389 — GitHub Copilot Filesystem Exfiltration CVSS 7.5. Indirect prompt injection via fetch_webpage reads files outside workspace. Source code, API keys, configs at risk. 🔗 https://threataft.com/articles/cve-2025-66389-github-copilot-fetchpage-file-read #CyberSecurity #ThreatIntel #infosec #GitHubCopilot

    Post summary

    The tweet announces CVE-2025-66389, detailing a filesystem exfiltration flaw in GitHub Copilot’s fetch_webpage function with a CVSS score of 7.5 and highlights potential data exposure.

    0000085
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftgithub_copilot1.372.0visual_studio_code-

Explore more