Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -8%vs 48 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
79 items
CVE-2026-47282: GitHub Copilot and Visual Studio Code insufficiently protected credentials
Jul 14, 2026MediumVulnerabilitySecurityCVE-2026-47282CVE-2026-47282 describes insufficiently protected credentials in GitHub Copilot and Visual Studio Code that allow an unauthorized attacker to disclose information over a network. The weakness is mapped to CWE-200 and CWE-522. NVD published the entry on 07/14/2026, and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-41106: M365 Copilot open redirect to untrusted site enabling privilege elevation
Jul 2, 2026CriticalVulnerabilitySecurityCVE-2026-41106CVE-2026-41106 is a URL redirection to untrusted site ('open redirect') flaw, CWE-601, in M365 Copilot. The source says an unauthorized attacker can exploit it over a network to elevate privileges. NVD has not yet provided an assessment, and the NVD published and last modified dates are both 07/02/2026.
NVD/CVE DatabaseCVE-2026-54322: Daytona role update and delete endpoints allow cross-organization changes
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54322Prior to 0.185.0, Daytona's organization role update and delete endpoints checked that the caller owned the organization in the request path, but located the target role by identifier alone. An authenticated user who owns any organization could modify or delete a role belonging to a different organization if they knew that role's identifier. The flaw is tracked as CVE-2026-54322.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseCVE-2026-54321: Daytona sandbox previews reachable without authentication when private
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54321CVE-2026-54321 affects Daytona from 0.101.0 until 0.184.0. Sandbox previews switched from public to private could stay reachable without authentication for a short period, because a cached visibility state was not invalidated when the sandbox's visibility changed. The weakness is classified as CWE-613 (Insufficient Session Expiration) and CWE-863 (Incorrect Authorization).
Fix: This vulnerability is fixed in 0.184.0.
NVD/CVE DatabaseCVE-2026-54320: Daytona organization invitation acceptance without verified email
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54320CVE-2026-54320 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.184.0. The organization invitation accept and decline paths did not require the matching email to be verified, although organization creation did. On identity providers that allow self-service signup and issue a session before email verification, an actor could register an unverified address matching a pending invitation, accept it, and join the target organization with the invitation's role, up to Owner.
Fix: Fixed in 0.184.0.
NVD/CVE DatabaseCVE-2026-54319: Daytona path traversal in sandbox volume bind-mount source resolution
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54319CVE-2026-54319 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.186. A sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement, so a reference containing path-traversal sequences could in principle resolve the mount source outside the intended per-volume base directory.
Fix: Fixed in 0.186.
NVD/CVE DatabaseCVE-2026-54324: Daytona cross-tenant authorization flaw in notification WebSocket gateway
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54324CVE-2026-54324 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.185.0. A cross-tenant authorization flaw in its notification WebSocket gateway let any authenticated user subscribe to another organization's realtime notification channel and passively receive that organization's events.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseCVE-2026-54323: Daytona git clone skips TLS certificate verification, exposing credentials
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54323Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.185.0 disabled TLS certificate verification in the daemon's git clone implementation on both the go-git and native git CLI code paths. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header over an unvalidated connection. An attacker able to intercept clone traffic could present any TLS certificate, capture those credentials, and serve tampered repository content into the sandbox.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseCVE-2026-45482: GitHub Copilot and Visual Studio Code path traversal flaw
Jun 9, 2026HighVulnerabilitySecurityCVE-2026-45482CVE-2026-45482 is a path traversal flaw (CWE-22) in GitHub Copilot and Visual Studio Code. The source says it allows an unauthorized attacker to bypass a security feature locally. NIST has not yet provided an NVD assessment, and Microsoft Corporation is the listed source.
NVD/CVE DatabaseCVE-2026-47644: Copilot Chat in Microsoft Edge injection flaw allows information disclosure
Jun 4, 2026MediumVulnerabilitySecurityCVE-2026-47644CVE-2026-47644 is an improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge), classified as CWE-74. The source states that it allows an unauthorized attacker to disclose information over a network. The NVD assessment has not yet been provided.
NVD/CVE DatabaseCVE-2026-45497: Microsoft Copilot command injection allowing remote code execution
Jun 4, 2026HighVulnerabilitySecurityCVE-2026-45497CVE-2026-45497 is a command injection flaw (CWE-77) in Microsoft Copilot, classified as Improper Neutralization of Special Elements used in a Command. The source says an authorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published and last modified on 06/04/2026.
NVD/CVE DatabaseCVE-2026-42824: M365 Copilot command injection allows unauthorized information disclosure
Jun 4, 2026MediumVulnerabilitySecurityCVE-2026-42824CVE-2026-42824 is an improper neutralization of special elements used in a command ('command injection') flaw, classified as CWE-77, in M365 Copilot. The source states that an unauthorized attacker can disclose information over a network. The record was published and last modified on 06/04/2026, with the CVE attributed to Microsoft Corporation and no NVD assessment yet provided.
NVD/CVE DatabaseCVE-2026-45033: GitHub Copilot CLI code execution via nested malicious bare git repository
May 13, 2026HighVulnerabilitySecurityCVE-2026-45033A flaw in GitHub Copilot CLI before 1.0.43 allows arbitrary code execution when the agent runs git operations inside a project containing a malicious nested bare git repository. Git's automatic bare repository discovery during directory traversal lets an attacker set core.fsmonitor or other executable config keys, such as core.hookspath, diff.external and merge.tool, which git runs during status, diff or rev-parse without user awareness or approval.
Fix: Fixed in 1.0.43.
NVD/CVE DatabaseCVE-2026-42893: M365 Copilot command injection allowing network tampering
May 12, 2026HighVulnerabilitySecurityCVE-2026-42893CVE-2026-42893 is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), in M365 Copilot. The source states that an unauthorized attacker can perform tampering over a network. NVD had not yet provided an assessment at the time of the record.
NVD/CVE DatabaseCVE-2026-41614: M365 Copilot for Desktop improper access control allows local spoofing
May 12, 2026MediumVulnerabilitySecurityCVE-2026-41614CVE-2026-41614 is an improper access control flaw (CWE-284) in M365 Copilot for Desktop. It allows an unauthorized attacker to perform spoofing, but only locally. NIST has not yet provided an NVD assessment, and the source is Microsoft Corporation, published 05/12/2026.
NVD/CVE DatabaseCVE-2026-41109: GitHub Copilot and Visual Studio injection flaw bypasses security feature
May 12, 2026HighVulnerabilitySecurityCVE-2026-41109CVE-2026-41109 is an improper neutralization of special elements in output used by a downstream component ('injection'), classified as CWE-74, in GitHub Copilot and Visual Studio. The source states that an unauthorized attacker can bypass a security feature over a network. NVD published the entry on 05/12/2026, and NIST has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-41100: M365 Copilot improper access control allows local spoofing
May 12, 2026MediumVulnerabilitySecurityCVE-2026-41100CVE-2026-41100 is an improper access control flaw (CWE-284) in M365 Copilot. The source states that an authorized attacker can perform spoofing locally. NVD had not yet provided an assessment when the record was published on 05/12/2026.
NVD/CVE DatabaseCVE-2026-42869: SOCFortress CoPilot hardcoded JWT signing secret allows forged admin tokens
May 11, 2026CriticalVulnerabilitySecurityCVE-2026-42869CVE-2026-42869 affects SOCFortress CoPilot before 0.1.57. The backend ships a hardcoded JWT signing secret as a fallback in backend/app/auth/utils.py:28 and repeats it in .env.example. Deployments that leave JWT_SECRET unset, including the default Docker Compose setup, sign every authentication token with this public value, letting an unauthenticated attacker forge admin-scoped JWTs and take full control of the application and the security tools it manages.
Fix: Fixed in 0.1.57.
NVD/CVE DatabaseCVE-2026-33111: Copilot Chat (Microsoft Edge) command injection allowing information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-33111CVE-2026-33111 is a command injection flaw (CWE-77) in Copilot Chat for Microsoft Edge. Per the source, an unauthorized attacker can exploit it over a network to disclose information. NIST has not yet provided an NVD assessment, and the entry was published and last modified on 05/07/2026.
NVD/CVE DatabaseCVE-2026-26164: M365 Copilot injection flaw allows unauthorized information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-26164CVE-2026-26164 is an improper neutralization of special elements in output used by a downstream component ('injection'), classified as CWE-74, in M365 Copilot. The source states that an unauthorized attacker can disclose information over a network. NVD has not yet provided an assessment, and the record was published and last modified on 05/07/2026.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.