Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 41
- Change
- -16%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 5 |
| Sep 2025 | 1 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 20 |
| Mar 2026 | 15 |
| Apr 2026 | 14 |
| May 2026 | 16 |
| Jun 2026 | 17 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 12 |
| Oct 2026 | 2 |
160 items
CVE-2026-24301: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-24301CVE-2026-24301, filed under CWE-77, is an improper neutralization of special elements in a command in Microsoft Copilot. Per the source, an unauthorized attacker can disclose information over a network. NVD had not yet provided an assessment at publication, which was 08/18/2026.
NVD/CVE DatabaseWiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”
Aug 17, 2026MediumNewsSecurityIndustryWiz Research's Red Agent, an autonomous AI-powered security research tool, found a script injection vulnerability in snowflakedb/snowflake-connector-net through Snowflake's HackerOne program. The jira_issue.yml GitHub Actions workflow, triggered by issues opened, interpolated the attacker-controlled issue title into a shell script, letting any GitHub user run arbitrary commands on a runner by opening a crafted issue. The flaw was introduced on June 18, 2026 by PR #1218, co-authored by Copilot Autofix, and Wiz disclosed it on June 23, 2026.
Fix: Snowflake remediated the vulnerability on the same day it was disclosed, rotated the affected credential, and verified via audit logs that Wiz was the sole actor during the exposure window.
Wiz Research BlogMicrosoft’s Clippy-like Mico character is no longer the face of Copilot
Aug 13, 2026InfoNewsIndustryMicrosoft will stop showing its Mico avatar in Copilot's voice mode and move it to the Learn Live platform, where it will have more to react to, according to a Microsoft support page. Mico launched in Copilot's voice mode last October, and Microsoft AI CEO Mustafa Suleyman pitched it as a way to give the chatbot an identity.
The Verge (AI)Microsoft is combining its Copilot apps ahead of a ‘super app’
Aug 13, 2026InfoNewsIndustryMicrosoft is merging its consumer and commercial Copilot AI assistants into a single "super app" interface, starting with the Copilot and Microsoft 365 Copilot apps. Personal and work accounts will move to the unified app, which keeps the "Microsoft Copilot" name and gets a new icon.
The Verge (AI)CVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual…
Aug 11, 2026HighVulnerabilitySecurityCVE-2026-70335CVE-2026-70335 is an OS command injection flaw (CWE-78) in GitHub Copilot and Visual Studio Code. The source says an unauthorized attacker can elevate privileges locally. NVD has not yet provided an assessment, and Microsoft Corporation is listed as the source.
NVD/CVE DatabaseCVE-2026-65675: No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security…
Aug 11, 2026HighVulnerabilitySecurityCVE-2026-65675CVE-2026-65675 affects the Visual Studio Code Copilot Chat Extension. The description states that an unauthorized attacker can bypass a security feature over a network. No CWE is assigned for this issue, and NVD had not yet provided an assessment at the time of the source text.
NVD/CVE DatabaseCVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to…
Aug 8, 2026CriticalVulnerabilitySecurityCVE-2026-14526The AI Copilot – Content Generator WordPress plugin, in all versions up to and including 1.5.6, fails to verify user authorization. Unauthenticated attackers can save and run a malicious workflow containing a wp_create_user action node with role=administrator, creating an administrator account and taking over the site. The waic-nonce value is emitted into public JavaScript (WAIC_DATA.waicNonce) on pages where the [aiwu-form] shortcode or public chatbot is rendered, so the nonce check provides no real barrier. Any site rendering those components on a frontend page is exposed.
NVD/CVE DatabaseCopilot worm can spread through Microsoft Word docs
Jul 30, 2026MediumNewsSecurityIndustryNorwegian AI researcher Håkon Måløy reported that an attacker can hide instructions in a Word document that Copilot later uses as source material, so the malicious instructions can alter figures in the newly generated document and copy themselves into it. Microsoft confirmed the report and said it addressed the findings, but Måløy said the core vulnerability had not yet been fixed when he published.
Fix: Microsoft said it uses a defense-in-depth strategy with safeguards that block malicious instructions at multiple points, is continuously strengthening these safeguards, and encourages customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it. Måløy said the multiple small focused mitigations Microsoft implemented can reduce the demonstrated attack surface, though they do not eliminate the underlying problem.
CSO OnlineMicrosoft confirms an AI worm is propagating through Copilot and other MS apps
Jul 30, 2026MediumNewsSecuritySafetyNorwegian AI researcher Håkon Måløy published details of an AI worm that spreads through Microsoft Word and Copilot. An attacker can hide instructions in a document used as source material for Copilot-generated or Copilot-edited Word documents, where they can alter figures and copy themselves into new documents that carry the attack into other Copilot-assisted workflows. Microsoft confirmed the findings and said it has addressed them.
Fix: Microsoft says it has addressed the findings and uses a defense-in-depth strategy with safeguards that block malicious instructions at multiple points. Microsoft encourages customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it. Måløy reports that the core vulnerability has yet to be fixed, though Microsoft's mitigations reduce the demonstrated attack surface.
CSO OnlineMicrosoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Jul 30, 2026MediumNewsSecurityIndustryHåkon Måløy disclosed a technique in which hidden instructions in a Word document make Microsoft 365 Copilot halve financial figures in a report and copy the same instructions, in white eight-point text, into the finished file. The chain spreads only through further Copilot drafting or editing operations, and the disclosure reports no exploitation in the wild and no public CVE. Måløy says the attack class still reproduced on July 28, after Microsoft deployed two mitigations.
Fix: Microsoft deployed two mitigations: the first blocked the original prompt wording, and the second upgraded the underlying model to GPT-5.5. Måløy recommends treating external documents as untrusted, reviewing attached documents before starting a generation or edit, and checking Copilot-generated or edited files before reuse or sharing.
The Hacker NewsFalcon AIDR Now Protects Copilot Studio Agents and Claude Code
Jul 30, 2026InfoNewsSecurityIndustryCrowdStrike's Falcon AI Detection and Response (AIDR) now extends its AI visibility, detection, and response to Microsoft Copilot Studio and Claude Code, plus a Falcon browser extension capability. In Copilot Studio, Falcon AIDR runs as an external threat detection provider and returns allow or block decisions on tool calls before they execute. For Claude Code, it connects to the tool's hook event system to check prompts and tool activity, with setup done by adding a JSON block to the settings file.
CrowdStrike BlogMicrosoft confirms Copilot ‘super app’ coming this year
Jul 29, 2026InfoNewsIndustryMicrosoft is building an AI "super app" that combines Copilot's chat, coding, and agentic capabilities. CEO Satya Nadella confirmed on an earnings call that it will span consumer and commercial experiences when it launches this year.
The Verge (AI)CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Jul 23, 2026CriticalVulnerabilitySecurityCVE-2026-50517CVE-2026-50517 is a deserialization of untrusted data flaw (CWE-502) in M365 Copilot. The source says an authorized attacker can exploit it over a network to execute code. NVD has not yet provided an assessment, and the source lists Microsoft Corporation as the CVE source.
NVD/CVE DatabaseCVE-2026-13009: The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]'…
Jul 23, 2026MediumVulnerabilitySecurityCVE-2026-13009CVE-2026-13009 affects the AI Copilot – Content Generator WordPress plugin in all versions up to and including 1.5.4. Insufficient escaping of the order[0][dir] parameter and a lack of prepared statements allow authenticated attackers with subscriber-level access or higher to append SQL queries to existing ones and extract sensitive database information. The waic-nonce is exposed on the front-end when the [waic_form] or [aiwu-form] shortcode renders, so contributor-level users who can publish shortcodes can obtain it and reach the vulnerable AJAX handler, which checks only the nonce when the shortcodes are not already embedded in a page.
NVD/CVE DatabaseCVE-2026-9810: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val…
Jul 17, 2026CriticalVulnerabilitySecurityCVE-2026-9810CVE-2026-9810 affects the AI Copilot WordPress plugin before 1.5.4. The plugin does not bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. Unauthenticated attackers who complete the public OAuth flow can run privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
NVD/CVE DatabaseWhy Jim Cramer is shocked by Citi's against-the-grain praise of Microsoft's Copilot
Jul 15, 2026InfoNewsIndustryCNBC TechnologyCVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a…
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-58617CVE-2026-58617 describes improper access control (CWE-284) in Microsoft 365 Copilot for iOS. An unauthorized attacker can elevate privileges over a network. The NVD has not yet provided an assessment, and the vulnerability was published on 07/14/2026.
NVD/CVE DatabaseCVE-2026-55145: Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an…
Jul 14, 2026MediumVulnerabilitySecurityCVE-2026-55145CVE-2026-55145 is a command injection flaw (CWE-77) in Outlook Copilot, caused by improper neutralization of special elements used in a command. The source says an authorized attacker can perform tampering over a network. NVD had not yet provided an assessment at the time of publication on 07/14/2026.
NVD/CVE DatabaseCVE-2026-50510: Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to…
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-50510CVE-2026-50510 is an improper restriction of names for files and other resources in GitHub Copilot, classified as CWE-641. According to the source, an unauthorized attacker can execute code locally. NVD has not yet provided an assessment, and the source gives no CVSS score or affected version range.
NVD/CVE DatabaseCVE-2026-48561: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…
Jul 14, 2026CriticalVulnerabilitySecurityCVE-2026-48561CVE-2026-48561 is an improper neutralization of special elements used in a command, classified as CWE-77 (command injection), in Microsoft Copilot. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 07/14/2026.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.