CVE-2026-45033Disclosure(github / copilot-cli)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations. By exploiting git's automatic bare repository discovery during directory traversal, an attacker can set core.fsmonitor or other executable config keys to run arbitrary commands without user awareness or approval. The vulnerability arises because git's core.fsmonitor config key (and 15+ similar keys such as core.hookspath, diff.external, merge.tool, etc.) can specify arbitrary shell commands that git will execute as part of normal operations like status, diff, or rev-parse. This vulnerability is fixed in 1.0.43.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-696

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot-cli

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
copilot-cli

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-15: 2Technical Details · 2026-05-15: 205-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-45033: GitHub Copilot CLI Hit by RCE Vulnerability https://thecybrdef.com/cve-2026-45033-github-copilot-cli-rce-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    A newly reported CVE-2026-45033 affecting GitHub Copilot CLI is identified as an RCE vulnerability, with no evidence of PoC, active exploitation or patches mentioned.

    0000042
    5 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-45033: GitHub Copilot CLI Hit by RCE Vulnerability https://thecybrdef.com/cve-2026-45033-github-copilot-cli-rce-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    A new remote code execution vulnerability, CVE-2026-45033, affecting GitHub Copilot CLI has been disclosed via a news link.

    0000050
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubcopilot-cli---

Explore more