CVE-2026-29783Disclosure(github / copilot_command_line_interface)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server responses, or user instructions) can exploit bash parameter transformation operators to execute hidden commands, bypassing the safety assessment that classifies commands as "read-only." This has been patched in version 0.0.423. The vulnerability stems from how the CLI's shell safety assessment evaluates commands before execution. The safety layer parses and classifies shell commands as either read-only (safe) or write-capable (requires user approval). However, several bash parameter expansion features can embed executable code within arguments to otherwise read-only commands, causing them to appear safe while actually performing arbitrary operations. The specific dangerous patterns are ${var@P}, ${var=value} / ${var:=value}, ${!var}, and nested $(cmd) or <(cmd) inside ${...} expansions. An attacker who can influence command text sent to the shell tool - for example, through prompt injection via malicious repository content (README files, code comments, issue bodies), compromised or malicious MCP server responses, or crafted user instructions containing obfuscated commands - could achieve arbitrary code execution on the user's workstation. This is possible even in permission modes that require user approval for write operations, since the commands can appear to use only read-only utilities to ultimately trigger write operations. Successful exploitation could lead to data exfiltration, file modification, or further system compromise.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot_command_line_interface

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
copilot_command_line_interface

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-16: 1Technical Details · 2026-03-06: 103-0603-0703-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting GitHub copilot-cli (CVE-2026-29783) https://vuldb.com/?id.349509

    Post summary

    A newly identified vulnerability (CVE-2026-29783) affecting GitHub copilot-cli has an increased severity rating, but the post provides no technical details or mitigation information.

    01001125
    2.1K followersView on X
  • SQ1 Security@sq1_security
    Disclosure

    Attackers may start living off AI. CVE-2026-29783 shows how AI coding assistants can become attack vectors, creating a new security risk. Read more: https://www.sq1.security/blogs/the-copilot-paradox-when-ai-coding-tools-become-attack-vectors #CyberSecurity #CVE #AISecurity #SQ1Security https://t.co/nVZwNVN63i

    Post summary

    The tweet announces CVE-2026-29783, stating that AI coding assistants can become attack vectors, but it provides no PoC, exploit, patch, or technical details.

    0001060
    497 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29783 The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns.… https://www.cve.org/CVERecord?id=CVE-2026-29783

    Post summary

    GitHub Copilot CLI versions 0.0.422 and earlier can be exploited for arbitrary code execution through crafted bash parameter expansion patterns; no patch or active exploitation details are provided.

    0000089
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubcopilot_command_line_interface---

Explore more