CVE-2025-64671 is a high-severity command injection vulnerability affecting Microsoft GitHub Copilot. This flaw allows a local, authenticated attacker to execute arbitrary code on the system due to improper neutralization of special elements in a command. The vulnerability carries a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability with low attack complexity. While there is no public exploit code or evidence of active exploitation (not in KEV or Hot List), the vulnerability has garnered significant community attention and media coverage, with five articles and five community mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.60-243CPE matchmatch criteria | cpe:2.3:a:microsoft:github_copilot:*:*:*:*:*:jetbrains:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.