CVE-2026-29783 is a high-severity arbitrary code execution vulnerability affecting GitHub Copilot CLI versions up to 0.0.422. Attackers can exploit crafted bash parameter expansion patterns to bypass the CLI's safety assessment, allowing hidden commands to execute even when appearing read-only. This can lead to data exfiltration, file modification, or system compromise. The vulnerability has a CVSS score of 7.5 and is not currently known to be actively exploited, nor is there public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.423CPE matchmatch criteria | cpe:2.3:a:github:copilot_command_line_interface:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.