CVE-2026-50510CWE-641

GitHub Copilot Remote Code Execution Vulnerability

High · published July 14, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
29.0
In the wild
Unconfirmed
What it is

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00359 · 29.0th percentile
Weakness
CWE-641 · Improper Restriction of Names for Files and Other Resources
Published
2026-07-14T17:08Z
EPSS history
Timeline
  • 14 JUL 17:08Z
    GitHub Copilot Remote Code Execution Vulnerability
    cvelistv5