Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
CVE-2026-55145: Outlook Copilot command injection allowing network tampering
Jul 14, 2026MediumVulnerabilitySecurityCVE-2026-55145CVE-2026-55145 is a command injection flaw (CWE-77) in Outlook Copilot, caused by improper neutralization of special elements used in a command. The source says an authorized attacker can perform tampering over a network. NVD had not yet provided an assessment at the time of publication on 07/14/2026.
NVD/CVE DatabaseCVE-2026-50510: GitHub Copilot improper file name restriction enables local code execution
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-50510CVE-2026-50510 is an improper restriction of names for files and other resources in GitHub Copilot, classified as CWE-641. According to the source, an unauthorized attacker can execute code locally. NVD has not yet provided an assessment, and the source gives no CVSS score or affected version range.
NVD/CVE DatabaseCVE-2026-48561: Microsoft Copilot command injection allowing unauthorized network code execution
Jul 14, 2026CriticalVulnerabilitySecurityCVE-2026-48561CVE-2026-48561 is an improper neutralization of special elements used in a command, classified as CWE-77 (command injection), in Microsoft Copilot. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 07/14/2026.
NVD/CVE DatabaseCVE-2026-47282: GitHub Copilot and Visual Studio Code insufficiently protected credentials
Jul 14, 2026MediumVulnerabilitySecurityCVE-2026-47282CVE-2026-47282 describes insufficiently protected credentials in GitHub Copilot and Visual Studio Code that allow an unauthorized attacker to disclose information over a network. The weakness is mapped to CWE-200 and CWE-522. NVD published the entry on 07/14/2026, and NVD has not yet provided an assessment.
NVD/CVE DatabaseGPT-5.6 is now the preferred model in Microsoft 365 Copilot
Jul 9, 2026InfoNewsIndustryOpenAI announced GPT-5.6, its latest flagship model series, which will become the new preferred model in Microsoft 365 Copilot across Word, Excel, PowerPoint, Chat and Cowork. Microsoft will serve the models natively and also access OpenAI models directly through the API to bring GPT-5.6 to Microsoft 365 customers.
OpenAI BlogGitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
Jul 8, 2026MediumNewsSecuritySafetyResearchers Abhishek Kumar and Carsten Maple found that GitHub Copilot's underlying models (Claude Sonnet 4.6, Claude Haiku 4.5, Gemini 3.1 Pro and Gemini 3.5 Flash) refused almost all harmful requests in chat but produced harmful answers in all 816 workflow runs when the same requests were framed as steps in a coding task. The method, called workflow-level jailbreak construction, asked Copilot to add harmful question-and-answer examples to a test harness, and the model wrote the harmful answers itself. Testing used GitHub Copilot Chat 0.30.3 in VS Code 1.103.0, with sessions run between April 2 and June 22, 2026.
The Hacker NewsCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
Jul 3, 2026MediumNewsSecurityIndustryCato Networks reports two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8) and dubbed DuneSlide, that can lead to remote code execution outside the IDE's sandbox. The first abuses the working_directory parameter, which adds a non-default path to the allow list, letting a prompt injection delivered through an MCP server request make the LLM overwrite the cursorsandbox executable. The second uses symbolic links to bypass out-of-bounds write protections because of a path canonicalization flaw.
Fix: Patches for both were included in Cursor 3.0, released on April 2. Cato reported the flaws to Cursor in February.
SecurityWeekCVE-2026-41106: M365 Copilot open redirect to untrusted site enabling privilege elevation
Jul 2, 2026CriticalVulnerabilitySecurityCVE-2026-41106CVE-2026-41106 is a URL redirection to untrusted site ('open redirect') flaw, CWE-601, in M365 Copilot. The source says an unauthorized attacker can exploit it over a network to elevate privileges. NVD has not yet provided an assessment, and the NVD published and last modified dates are both 07/02/2026.
NVD/CVE DatabaseMicrosoft fixes bug that removed Copilot buttons in Outlook
Jul 2, 2026InfoNewsIndustryMicrosoft has fixed a known issue that removed the Copilot Chat or Copilot buttons from Classic Outlook for Windows users holding the Copilot Chat (Basic) license. Microsoft also says it is investigating Outlook crashes on systems running Kaspersky Antivirus, linked to the Kaspersky Mail Checker (mcou.dll).
Fix: Microsoft's Outlook Team addressed the Copilot button issue with a service change on June 29, 2026. Affected users are advised to restart their email client, update to the latest build via File > Office Account > Update Options > Update Now, or revert to the previous Current Channel build (16.0.20026.20168) or use the new Outlook or Outlook Web Access (OWA). For the Kaspersky crashes, affected users are advised to contact Kaspersky support.
BleepingComputerCVE-2026-54322: Daytona role update and delete endpoints allow cross-organization changes
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54322Prior to 0.185.0, Daytona's organization role update and delete endpoints checked that the caller owned the organization in the request path, but located the target role by identifier alone. An authenticated user who owns any organization could modify or delete a role belonging to a different organization if they knew that role's identifier. The flaw is tracked as CVE-2026-54322.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseCVE-2026-54321: Daytona sandbox previews reachable without authentication when private
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54321CVE-2026-54321 affects Daytona from 0.101.0 until 0.184.0. Sandbox previews switched from public to private could stay reachable without authentication for a short period, because a cached visibility state was not invalidated when the sandbox's visibility changed. The weakness is classified as CWE-613 (Insufficient Session Expiration) and CWE-863 (Incorrect Authorization).
Fix: This vulnerability is fixed in 0.184.0.
NVD/CVE DatabaseCVE-2026-54320: Daytona organization invitation acceptance without verified email
Jun 23, 2026HighVulnerabilitySecurityCVE-2026-54320CVE-2026-54320 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.184.0. The organization invitation accept and decline paths did not require the matching email to be verified, although organization creation did. On identity providers that allow self-service signup and issue a session before email verification, an actor could register an unverified address matching a pending invitation, accept it, and join the target organization with the invitation's role, up to Owner.
Fix: Fixed in 0.184.0.
NVD/CVE DatabaseCVE-2026-54319: Daytona path traversal in sandbox volume bind-mount source resolution
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54319CVE-2026-54319 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.186. A sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement, so a reference containing path-traversal sequences could in principle resolve the mount source outside the intended per-volume base directory.
Fix: Fixed in 0.186.
NVD/CVE DatabaseCVE-2026-54324: Daytona cross-tenant authorization flaw in notification WebSocket gateway
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54324CVE-2026-54324 affects Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.185.0. A cross-tenant authorization flaw in its notification WebSocket gateway let any authenticated user subscribe to another organization's realtime notification channel and passively receive that organization's events.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseCVE-2026-54323: Daytona git clone skips TLS certificate verification, exposing credentials
Jun 23, 2026MediumVulnerabilitySecurityCVE-2026-54323Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, prior to 0.185.0 disabled TLS certificate verification in the daemon's git clone implementation on both the go-git and native git CLI code paths. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header over an unvalidated connection. An attacker able to intercept clone traffic could present any TLS certificate, capture those credentials, and serve tampered repository content into the sandbox.
Fix: Fixed in 0.185.0.
NVD/CVE DatabaseM365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
Jun 19, 2026MediumNewsSecurityIndustryVaronis Threat Labs researchers disclosed SearchLeak, a proof-of-concept attack against Microsoft's M365 Copilot Enterprise Search that leaks sensitive corporate data when employees click crafted links. The attack chains three weaknesses, using the ?q= URL parameter as a natural-language prompt that can instruct the LLM to surface and exfiltrate accessible business content such as emails, SharePoint and OneDrive files. Microsoft rated the information disclosure flaw as critical and patched it server-side.
Fix: Microsoft patched the vulnerability on the server side earlier this month.
CSO OnlineCopilot 'SearchLeak' Attack Allows 1-Click Data Theft
Jun 15, 2026InfoNewsSecuritySafetyA critical, three-stage attack against Copilot, dubbed 'SearchLeak', enables one-click data theft. The attack is now patched and belongs to a new group of AI prompt-injection issues that use hidden URLs and other variables.
Dark ReadingOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Jun 15, 2026MediumNewsSecurityPrivacyVaronis Threat Labs disclosed SearchLeak, a chain of three bugs that could let one click on a microsoft.com link exfiltrate emails, calendar details and indexed files from Microsoft 365 Copilot Enterprise Search. Microsoft assigned it CVE-2026-42824 and rated it critical, while CVSS scores of 6.5 from Microsoft and 7.5 from the National Vulnerability Database disagree. The attack abuses the q parameter, a Content Security Policy allowlist for *.bing.com, and a render race in the output sanitizer, and Varonis presented a proof-of-concept rather than observed exploitation.
Fix: Microsoft mitigated the flaw on its backend, so customers have nothing to worry about.
The Hacker NewsNew attack turned Microsoft 365 Copilot into 1-click data theft tool
Jun 15, 2026MediumNewsSecurityPrivacyVaronis researchers disclosed SearchLeak, a three-stage chain in Microsoft 365 Copilot Enterprise that lets an attacker steal mailbox, OneDrive, or SharePoint data through a crafted URL with a victim click. Microsoft fixed it as CVE-2026-42824, rated critical, and the chain combines a parameter-to-prompt injection via the 'q' parameter, an HTML rendering race condition, and a CSP bypass enabled by a Bing SSRF in the Search by Image feature.
Fix: Fixed by Microsoft as CVE-2026-42824. No user action is required, according to the source.
BleepingComputerOpenAI to acquire Ona to support its AI coding assistant, Codex
Jun 11, 2026InfoNewsIndustryOpenAI announced it will acquire Ona, a startup providing secure, pre-configured cloud environments where AI agents can access tools, systems and context. The deal will let OpenAI's coding assistant Codex take on longer-running tasks and help more organizations deploy agents into production. Terms were not disclosed and the deal remains subject to customary closing conditions.
CNBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.