Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
79 items
CVE-2026-85887: M365 Copilot incorrect permission assignment allows information disclosure
Sep 17, 2026HighVulnerabilitySecurityPrivacyCVE-2026-85887CVE-2026-85887 is an incorrect permission assignment for a critical resource in M365 Copilot. An authorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-85885: M365 Copilot command injection allows privilege elevation over a network
Sep 17, 2026CriticalVulnerabilitySecurityCVE-2026-85885CVE-2026-85885 is an improper neutralization of special elements used in a command ('command injection') flaw in M365 Copilot. An authorized attacker can exploit it over a network to elevate privileges.
NVD/CVE DatabaseCVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business…
Sep 17, 2026HighVulnerabilitySecurityPrivacyCVE-2026-78501CVE-2026-78501 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft 365 Copilot's Business Chat. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-55946: Microsoft Copilot command injection allows unauthorized information disclosure
Sep 17, 2026MediumVulnerabilitySecurityCVE-2026-55946CVE-2026-55946 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft Copilot. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-81381: GitHub Copilot and Visual Studio Code credential exposure over network
Sep 8, 2026MediumVulnerabilitySecurityCVE-2026-81381CVE-2026-81381 describes insufficiently protected credentials in GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit this over a network to disclose information.
NVD/CVE DatabaseCVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio…
Sep 8, 2026MediumVulnerabilitySecurityCVE-2026-81380CVE-2026-81380 is a command injection flaw (CWE-77 style wording: improper neutralization of special elements used in a command) affecting GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-80098: Copilot Studio improper signature verification allows privilege elevation
Sep 3, 2026CriticalVulnerabilitySecurityCVE-2026-80098CVE-2026-80098 is an improper verification of cryptographic signature flaw in Copilot Studio. An unauthorized attacker can exploit it over a network to elevate privileges.
NVD/CVE DatabaseCVE-2026-58616: Copilot Chat (Microsoft Edge) race condition allows info disclosure
Aug 28, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-58616CVE-2026-58616 is a race condition (CWE-362, improper synchronization of a shared resource) in Copilot Chat in Microsoft Edge. An authorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-69855: Microsoft Copilot in Azure SSRF allows information disclosure
Aug 20, 2026HighVulnerabilitySecurityCVE-2026-69855CVE-2026-69855 is a server-side request forgery (SSRF) flaw in Microsoft Copilot in Azure, classified as CWE-918. An authorized attacker can exploit it over a network to disclose information. The source gives no CVSS score, as NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-24301: Microsoft Copilot command injection allows unauthorized information disclosure
Aug 18, 2026HighVulnerabilitySecurityCVE-2026-24301CVE-2026-24301, filed under CWE-77, is an improper neutralization of special elements in a command in Microsoft Copilot. Per the source, an unauthorized attacker can disclose information over a network. NVD had not yet provided an assessment at publication, which was 08/18/2026.
NVD/CVE DatabaseCVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual…
Aug 11, 2026HighVulnerabilitySecurityCVE-2026-70335CVE-2026-70335 is an OS command injection flaw (CWE-78) in GitHub Copilot and Visual Studio Code. The source says an unauthorized attacker can elevate privileges locally. NVD has not yet provided an assessment, and Microsoft Corporation is listed as the source.
NVD/CVE DatabaseCVE-2026-65675: Visual Studio Code CoPilot Chat Extension security feature bypass over network
Aug 11, 2026HighVulnerabilitySecurityCVE-2026-65675CVE-2026-65675 affects the Visual Studio Code Copilot Chat Extension. The description states that an unauthorized attacker can bypass a security feature over a network. No CWE is assigned for this issue, and NVD had not yet provided an assessment at the time of the source text.
NVD/CVE DatabaseCVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to…
Aug 8, 2026CriticalVulnerabilitySecurityCVE-2026-14526The AI Copilot – Content Generator WordPress plugin, in all versions up to and including 1.5.6, fails to verify user authorization. Unauthenticated attackers can save and run a malicious workflow containing a wp_create_user action node with role=administrator, creating an administrator account and taking over the site. The waic-nonce value is emitted into public JavaScript (WAIC_DATA.waicNonce) on pages where the [aiwu-form] shortcode or public chatbot is rendered, so the nonce check provides no real barrier. Any site rendering those components on a frontend page is exposed.
NVD/CVE DatabaseCVE-2026-50517: M365 Copilot deserialization of untrusted data over a network
Jul 23, 2026CriticalVulnerabilitySecurityCVE-2026-50517CVE-2026-50517 is a deserialization of untrusted data flaw (CWE-502) in M365 Copilot. The source says an authorized attacker can exploit it over a network to execute code. NVD has not yet provided an assessment, and the source lists Microsoft Corporation as the CVE source.
NVD/CVE DatabaseCVE-2026-13009: AI Copilot Content Generator plugin SQL injection via order parameter
Jul 23, 2026MediumVulnerabilitySecurityCVE-2026-13009CVE-2026-13009 affects the AI Copilot – Content Generator WordPress plugin in all versions up to and including 1.5.4. Insufficient escaping of the order[0][dir] parameter and a lack of prepared statements allow authenticated attackers with subscriber-level access or higher to append SQL queries to existing ones and extract sensitive database information. The waic-nonce is exposed on the front-end when the [waic_form] or [aiwu-form] shortcode renders, so contributor-level users who can publish shortcodes can obtain it and reach the vulnerable AJAX handler, which checks only the nonce when the shortcodes are not already embedded in a page.
NVD/CVE DatabaseCVE-2026-9810: AI Copilot WordPress plugin accepts OAuth tokens not bound to a user
Jul 17, 2026CriticalVulnerabilitySecurityCVE-2026-9810CVE-2026-9810 affects the AI Copilot WordPress plugin before 1.5.4. The plugin does not bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. Unauthenticated attackers who complete the public OAuth flow can run privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
NVD/CVE DatabaseCVE-2026-58617: Microsoft 365 Copilot for iOS improper access control flaw
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-58617CVE-2026-58617 describes improper access control (CWE-284) in Microsoft 365 Copilot for iOS. An unauthorized attacker can elevate privileges over a network. The NVD has not yet provided an assessment, and the vulnerability was published on 07/14/2026.
NVD/CVE DatabaseCVE-2026-55145: Outlook Copilot command injection allowing network tampering
Jul 14, 2026MediumVulnerabilitySecurityCVE-2026-55145CVE-2026-55145 is a command injection flaw (CWE-77) in Outlook Copilot, caused by improper neutralization of special elements used in a command. The source says an authorized attacker can perform tampering over a network. NVD had not yet provided an assessment at the time of publication on 07/14/2026.
NVD/CVE DatabaseCVE-2026-50510: GitHub Copilot improper file name restriction enables local code execution
Jul 14, 2026HighVulnerabilitySecurityCVE-2026-50510CVE-2026-50510 is an improper restriction of names for files and other resources in GitHub Copilot, classified as CWE-641. According to the source, an unauthorized attacker can execute code locally. NVD has not yet provided an assessment, and the source gives no CVSS score or affected version range.
NVD/CVE DatabaseCVE-2026-48561: Microsoft Copilot command injection allowing unauthorized network code execution
Jul 14, 2026CriticalVulnerabilitySecurityCVE-2026-48561CVE-2026-48561 is an improper neutralization of special elements used in a command, classified as CWE-77 (command injection), in Microsoft Copilot. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 07/14/2026.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.