Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -8%vs 48 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
79 items
CVE-2026-26129: M365 Copilot improper neutralization enables information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-26129CVE-2026-26129 is a vulnerability in M365 Copilot, classified under CWE-138 (Improper Neutralization of Special Elements). An unauthorized attacker can exploit it over a network to disclose information. NVD had not yet provided an assessment at publication, and the record was published and last modified on 05/07/2026 with Microsoft Corporation as the source.
NVD/CVE DatabaseCVE-2026-33102: M365 Copilot open redirect to untrusted site allows privilege elevation
Apr 23, 2026CriticalVulnerabilitySecurityCVE-2026-33102CVE-2026-33102 is an open redirect (CWE-601) in M365 Copilot, a hosted service. The flaw is a URL redirection to an untrusted site, which allows an unauthorized attacker to elevate privileges over a network. NVD has not yet provided an assessment; Microsoft Corporation is the source, and NVD published the entry on 04/23/2026.
NVD/CVE DatabaseCVE-2026-6874: ericc-ch copilot-api reliance on reverse DNS in /token Host handling
Apr 22, 2026MediumVulnerabilitySecurityCVE-2026-6874CVE-2026-6874 affects ericc-ch copilot-api up to 0.7.0. A manipulated Host argument sent to the /token endpoint of the Header Handler component can lead to reliance on reverse DNS resolution (CWE-350). The attack can be performed remotely, the exploit has been publicly disclosed, and the vendor did not respond to early contact. CVSS 4.0 base score is 5.3 (MEDIUM), assessed by VulDB; NIST has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-6662: ericc-ch copilot-api permissive cross-domain policy in CORS handling
Apr 20, 2026HighVulnerabilitySecurityCVE-2026-6662CVE-2026-6662 affects ericc-ch copilot-api up to 0.7.0. A flaw in the function cors of src/server.ts, in the Token Endpoint component, produces a permissive cross-domain policy that accepts untrusted domains. The attack can be launched remotely, and public exploit code exists. VulDB scores it CVSS 4.0 6.9 (MEDIUM), with weaknesses CWE-346 and CWE-942.
NVD/CVE DatabaseCVE-2026-23653: GitHub Copilot and Visual Studio Code command injection flaw
Apr 14, 2026MediumVulnerabilitySecurityCVE-2026-23653CVE-2026-23653 is a command injection flaw (CWE-77) in GitHub Copilot and Visual Studio Code. The source states that an authorized attacker can use it to disclose information over a network. NIST has not yet provided an NVD assessment, and the CVE was published on 04/14/2026.
NVD/CVE DatabaseCVE-2026-26137: Microsoft 365 Copilot Business Chat server-side request forgery over the network
Mar 19, 2026HighVulnerabilitySecurityCVE-2026-26137CVE-2026-26137 is a server-side request forgery (CWE-918) in Microsoft 365 Copilot's Business Chat. According to the description, an authorized attacker over a network can use it to elevate privileges. NVD has not yet provided an assessment, and the record was published on 03/19/2026.
NVD/CVE DatabaseCVE-2026-26136: Microsoft Copilot command injection allows unauthorized information disclosure
Mar 19, 2026MediumVulnerabilitySecurityCVE-2026-26136CVE-2026-26136 is a command injection weakness (CWE-77) in Microsoft Copilot, reported by Microsoft Corporation. The source describes it as an improper neutralization of special elements used in a command, which allows an unauthorized attacker to disclose information over a network. The NVD has not yet provided an assessment, and the record was published and last modified on 03/19/2026.
NVD/CVE DatabaseCVE-2026-24299: M365 Copilot command injection allows unauthorized information disclosure
Mar 19, 2026MediumVulnerabilitySecurityCVE-2026-24299CVE-2026-24299 is an improper neutralization of special elements used in a command (CWE-77, command injection) in M365 Copilot. An unauthorized attacker can exploit it over a network to disclose information. NIST has not yet provided an NVD assessment, and Microsoft Corporation is the listed source.
NVD/CVE DatabaseCVE-2026-26133: M365 Copilot AI command injection allows information disclosure
Mar 16, 2026HighVulnerabilitySecurityCVE-2026-26133CVE-2026-26133 describes an AI command injection flaw in M365 Copilot. The source states that an unauthorized attacker can exploit it over a network to disclose information. NVD has not yet provided an assessment, and the vulnerability was published on 03/16/2026.
NVD/CVE DatabaseGHSA-g8r9-g2v8-jv6f: GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
Mar 6, 2026HighVulnerabilitySecurityCVE-2026-29783GitHub Copilot CLI's shell tool contains a vulnerability in which crafted bash parameter expansion patterns (such as ${var@P}, assignment forms like ${var=value}, indirect ${!var}, and nested $(cmd) inside ${...}) can hide command execution inside commands the safety assessment classifies as read-only. An attacker who can influence the commands the agent runs, for example through prompt injection in repository files, MCP server responses, or user instructions, could achieve arbitrary code execution on the user's workstation, even in modes that require approval for write operations. The issue affects versions prior to 0.0.423.
Fix: Fixed in 0.0.423. The fix adds parse-time detection that downgrades commands containing dangerous ${...} expansion operators or nested command/process substitutions from read-only to write-capable, and unconditionally blocks such commands at the tool execution layer regardless of permission mode, including --yolo / autopilot.
GitHub Advisory DatabaseCVE-2026-21523: GitHub Copilot and Visual Studio race condition allowing network code execution
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21523CVE-2026-21523 is a time-of-check time-of-use (TOCTOU) race condition, classified as CWE-367, in GitHub Copilot and Visual Studio. The source states that an authorized attacker can exploit it to execute code over a network. NIST has not yet provided an NVD assessment, and the entry was published 02/10/2026.
NVD/CVE DatabaseCVE-2026-21518: GitHub Copilot and Visual Studio Code command injection bypass
Feb 10, 2026MediumVulnerabilitySecurityCVE-2026-21518CVE-2026-21518 is an improper neutralization of special elements used in a command (CWE-77, 'command injection') flaw in GitHub Copilot and Visual Studio Code. The source states that an unauthorized attacker can exploit it over a network to bypass a security feature. NVD has not yet provided an assessment, and the record was published 02/10/2026 and last modified 02/11/2026.
NVD/CVE DatabaseCVE-2026-21516: GitHub Copilot command injection allows remote code execution over a network
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21516CVE-2026-21516 is a command injection flaw (CWE-77) in GitHub Copilot, caused by improper neutralization of special elements used in a command. According to the source, an unauthorized attacker can execute code over a network. NVD had not yet provided an assessment when the record was last modified on 02/11/2026, and the source lists Microsoft Corporation as the advisory source.
NVD/CVE DatabaseCVE-2026-21257: GitHub Copilot and Visual Studio command injection allows privilege elevation
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21257CVE-2026-21257 is a command injection flaw (CWE-77) in GitHub Copilot and Visual Studio. The source says an authorized attacker can exploit it over a network to elevate privileges. NVD has not yet provided an assessment, and the NVD record was published 02/10/2026 and last modified 02/11/2026.
NVD/CVE DatabaseCVE-2026-21256: GitHub Copilot and Visual Studio command injection over network
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21256CVE-2026-21256 is an improper neutralization of special elements used in a command, also known as command injection (CWE-77), in GitHub Copilot and Visual Studio. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 02/10/2026.
NVD/CVE DatabaseCVE-2026-24307: M365 Copilot improper input validation allows information disclosure
Jan 22, 2026CriticalVulnerabilitySecurityCVE-2026-24307CVE-2026-24307 is an improper validation of specified type of input (CWE-1287) in M365 Copilot. According to the source, an unauthorized attacker can exploit it over a network to disclose information. NVD had not yet provided an assessment when the entry was published on 01/22/2026, and last modified 02/12/2026.
NVD/CVE DatabaseCVE-2026-21521: Copilot information disclosure via improper neutralization of escape sequences
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-21521CVE-2026-21521 is classified as CWE-150, Improper Neutralization of Escape, Meta, or Control Sequences, in Copilot. The source states that an unauthorized attacker can disclose information over a network. NVD has not yet provided an assessment, and the affected software configurations list is not populated in the source.
NVD/CVE DatabaseCVE-2026-21520: Copilot Studio exposure of sensitive information to unauthorized actor
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-21520CVE-2026-21520 is an exposure of sensitive information to an unauthorized actor in Copilot Studio. According to the source, an unauthenticated attacker can view sensitive information through a network attack vector. The weakness is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-62116: AI Copilot missing authorization allows access control bypass
Dec 31, 2025MediumVulnerabilitySecurityCVE-2025-62116CVE-2025-62116 is a Missing Authorization vulnerability (CWE-862) in Quadlayers AI Copilot, a WordPress plugin, affecting versions from n/a through 1.4.7. The flaw allows exploitation of incorrectly configured access control security levels. Patchstack reported the issue, and NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseCVE-2025-62998: WP AI CoPilot sensitive data exposure through sent data
Dec 18, 2025MediumVulnerabilitySecurityPrivacyCVE-2025-62998CVE-2025-62998 is an Insertion of Sensitive Information Into Sent Data (CWE-201) vulnerability in WP Messiah's WP AI CoPilot plugin, affecting versions from n/a through 1.2.7. The flaw allows retrieval of embedded sensitive data. NVD has not yet provided an assessment, and the record was published by Patchstack on 12/18/2025.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.