Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -8%vs 48 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
CVE-2025-59272: Copilot command injection allows local information disclosure
Oct 9, 2025CriticalVulnerabilitySecurityCVE-2025-59272CVE-2025-59272 is a command injection flaw (CWE-77) in Copilot, where improper neutralization of special elements in a command lets an unauthorized attacker perform information disclosure locally. NVD has not yet provided an assessment, and the vendor advisory is from Microsoft Corporation. The record was published on 10/09/2025 and last modified on 12/11/2025.
NVD/CVE DatabaseCVE-2025-59252: Copilot command injection allows unauthorized information disclosure
Oct 9, 2025CriticalVulnerabilitySecurityCVE-2025-59252CVE-2025-59252 is a command injection flaw (CWE-77) in Copilot, which the source says is an Exclusively Hosted Service. An unauthorized attacker can exploit it over a network to disclose information. NVD had not yet provided an assessment, and the record was published 10/09/2025 and last modified 12/11/2025.
NVD/CVE DatabaseCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedCVE-2025-58401: Obsidian GitHub Copilot Plugin stores GitHub API token in cleartext
Sep 5, 2025MediumVulnerabilitySecurityCVE-2025-58401CVE-2025-58401 affects the Obsidian GitHub Copilot Plugin in versions prior to 1.1.7. The plugin stores the GitHub API token in cleartext form (CWE-312), so an attacker may perform unauthorized operations on the linked GitHub account. JPCERT/CC assigned a CVSS 4.0 score of 5.1 (MEDIUM), and NVD had not yet provided an assessment.
Fix: Fixed in 1.1.7 (https://github.com/Pierrad/obsidian-github-copilot/releases/tag/1.1.7).
NVD/CVE DatabaseGitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)
Aug 12, 2025MediumNewsSecurityIndustryThis post describes a prompt injection flaw in GitHub Copilot and VS Code, tracked as CVE-2025-53773, that leads to full system compromise of the developer's machine. The attack places Copilot into YOLO mode by modifying the project's settings.json file. The author notes that agents able to write files and alter their own configuration or security-relevant settings can reach remote code execution, a pattern similar to one recently described for Amp.
Embrace The RedCVE-2025-53773: GitHub Copilot and Visual Studio command injection allowing local code execution
Aug 12, 2025HighVulnerabilitySecurityCVE-2025-53773CVE-2025-53773 is a command injection weakness (CWE-77) in GitHub Copilot and Visual Studio. The source states that it allows an unauthorized attacker to execute code locally. NVD has not yet provided its own assessment, and the entry was published on 08/12/2025 and last modified on 08/15/2025.
NVD/CVE DatabaseCVE-2025-53787: Microsoft 365 Copilot BizChat information disclosure vulnerability
Aug 7, 2025HighVulnerabilitySecurityCVE-2025-53787NIST's NVD entry for CVE-2025-53787 describes a Microsoft 365 Copilot BizChat information disclosure vulnerability, classified under CWE-77 (Improper Neutralization of Special Elements used in a Command, 'Command Injection'). The NVD published the entry on 08/07/2025 and last modified it on 08/14/2025, and NVD has not yet provided its own assessment. The source provides no attack details or affected version list.
NVD/CVE DatabaseCVE-2025-53774: Microsoft 365 Copilot BizChat information disclosure
Aug 7, 2025MediumVulnerabilitySecurityCVE-2025-53774CVE-2025-53774 is an information disclosure vulnerability in Microsoft 365 Copilot BizChat, an exclusively hosted service. It is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'). NVD published it on 08/07/2025 and last modified it on 08/14/2025, and NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseCVE-2025-32711: M365 Copilot AI command injection allows information disclosure over network
Jun 11, 2025CriticalVulnerabilitySecurityCVE-2025-32711CVE-2025-32711 describes an AI command injection flaw in M365 Copilot that lets an unauthorized attacker disclose information over a network. The weakness is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), and Microsoft is the listed source. NVD published the entry on 06/11/2025 and last modified it on 08/04/2025, and no NVD assessment was yet provided.
NVD/CVE DatabaseGitHub Copilot Custom Instructions and Risks
Apr 6, 2025LowNewsSecurityIndustryGitHub Copilot can be augmented with custom instructions from the current repo, read from the .github/copilot-instructions.md file. Pillar Security highlighted the risks of such rules files, using custom Cursor rules in ./cursor/rules ending in .mdc, and included a GitHub Copilot demo that uses copilot-instructions.md. GitHub then changed its Web UI to highlight invisible Unicode characters, citing the Pillar Security post and a post about ASCII Smuggling.
Fix: GitHub made a product change that highlights invisible Unicode characters in the Web UI.
Embrace The RedMicrosoft 365 Copilot Generated Images Accessible Without Authentication -- Fixed!
Jan 2, 2025MediumNewsSecurityIndustryThe author compares system prompt changes in Microsoft 365 Copilot (BizChat) over time and notes that a single enterprise_search tool used to exist. The tool was previously used in the Copirate ASCII Smuggling exploit to search a user's inbox for MFA codes.
Embrace The RedCVE-2024-49038: Copilot Studio cross-site scripting allows privilege elevation over network
Nov 26, 2024CriticalVulnerabilitySecurityCVE-2024-49038CVE-2024-49038 is an improper neutralization of input during web page generation ('Cross-site Scripting', CWE-79) in Copilot Studio. According to the source, an unauthorized attacker over a network can exploit it to elevate privilege. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2024-48140: Monica Your AI Copilot prompt injection in chatbox exposes chat data
Oct 24, 2024HighVulnerabilitySecurityCVE-2024-48140CVE-2024-48140 describes a prompt injection vulnerability in the chatbox of Butterfly Effect Limited's Monica Your AI Copilot powered by ChatGPT4, version 6.3.0. A crafted message lets an attacker access and exfiltrate all previous and subsequent chat data between the user and the AI assistant. The source lists CWE-77 (Command Injection) as the weakness, and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2024-43610: Copilot Studio exposure of sensitive information to unauthorized actor
Oct 9, 2024HighVulnerabilitySecurityCVE-2024-43610CVE-2024-43610 is an information exposure flaw (CWE-200) in Copilot Studio. An unauthenticated attacker can view sensitive information over the network. NIST has not yet provided an NVD assessment, and Microsoft is the listed source.
NVD/CVE DatabaseCVE-2024-9333: M-Files Connector for Copilot permissions bypass exposing limited documents
Oct 2, 2024MediumVulnerabilitySecurityCVE-2024-9333CVE-2024-9333 is a permissions bypass in the M-Files Connector for Copilot before version 24.9.3. Incorrect access control list calculation lets an authenticated user access a limited number of documents. The CNA, M-Files Corporation, scores it CVSS 4.0 5.3 (MEDIUM), and NVD has not yet provided an assessment.
NVD/CVE DatabaseMicrosoft Copilot: From Prompt Injection to Exfiltration of Personal Information
Aug 26, 2024MediumNewsSecurityPrivacyJohann Rehberger describes an exploit chain against Microsoft 365 Copilot that let an attacker steal a user's emails and personal information. The chain combines prompt injection delivered through a malicious email or shared document, automatic tool invocation to pull in other emails and documents, and ASCII Smuggling to hide data inside clickable hyperlinks to an attacker-controlled domain. Rehberger first reported parts of the exploit to Microsoft in January 2024 and the full chain in February 2024, and disclosed it after MSRC approval.
Embrace The RedCVE-2024-38206: Microsoft Copilot Studio SSRF protection bypass leaking sensitive information
Aug 6, 2024HighVulnerabilitySecurityCVE-2024-38206EPSS: 12.3%CVE-2024-38206 is a vulnerability in Microsoft Copilot Studio, classified under CWE-918 (Server-Side Request Forgery). An authenticated attacker can bypass the product's SSRF protection and leak sensitive information over a network. NVD published the entry on 08/06/2024 and last modified it on 08/13/2024, with no NVD assessment yet provided.
Fix: Microsoft's MSRC update guide entry for CVE-2024-38206 is listed as a Patch source, but the source text does not state the fix, fixed version or workaround. N/A -- no mitigation discussed in source.
NVD/CVE DatabaseProtect Your Copilots: Preventing Data Leaks in Copilot Studio
Jul 30, 2024InfoNewsSecurityPrivacyMicrosoft's Copilot Studio, a low-code platform for building chatbots, is the subject of this post. It covers data leak and unauthorized access risks, including how external adversaries can find and interact with misconfigured Copilots. The post highlights Data Loss Prevention (DLP) as a control that is currently off by default.
Fix: Enable Data Loss Prevention (DLP), which is currently off by default, to protect your organization's data.
Embrace The RedGitHub Copilot Chat: From Prompt Injection to Data Exfiltration
Jun 15, 2024MediumNewsSecurityIndustryA prompt injection flaw in the GitHub Copilot Chat VS Code extension allowed data exfiltration when the extension analyzed untrusted source code. The extension sends source code and user questions to a large language model, and the post describes how that input path could be abused. The source text does not give further technical detail in this excerpt.
Embrace The RedWho Am I? Conditional Prompt Injection Attacks with Microsoft Copilot
Mar 3, 2024MediumNewsSecuritySafetyA researcher found that Microsoft 365 Copilot can be attacked with conditional prompt injection payloads that behave differently depending on which user reads the content. The attacker embeds instructions in an email that check the recipient's name, so the payload activates only for specific targets. In a demo with three recipients, the researcher showed different outputs for each person.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.