Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-64671

28
FAUCET Score

CVE-2025-64671 is a high-severity command injection vulnerability affecting Microsoft GitHub Copilot. This flaw allows a local, authenticated attacker to execute arbitrary code on the system due to improper neutralization of special elements in a command. The vulnerability carries a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability with low attack complexity. While there is no public exploit code or evidence of active exploitation (not in KEV or Hot List), the vulnerability has garnered significant community attention and media coverage, with five articles and five community mentions.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.5.60-243CPE matchmatch criteria
cpe:2.3:a:microsoft:github_copilot:*:*:*:*:*:jetbrains:*:*

CVSS Data

CVSS version used by this source: 3.1

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 64th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: GitHub Copilot Plugin for JetBrains IDEsFixed in: 1.5.60-243
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2025-Dec/CVE-2025-64671Important

GitHub Copilot for Jetbrains Remote Code Execution Vulnerability

Dec 9, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-64671
Vendor Advisory