CVE-2025-66389: High severity GitHub GitHub Copilot vulnerability
Published Jun 22, 2026
·Updated
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetchwebpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Affected Software
2 affected components
GitHub GitHub Copilot=1.372.0
Microsoft Github Copilot Visual Studio Code=1.372.0
Event History
Jun 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66389?
The severity of CVE-2025-66389 is high with a CVSS score of 7.5.
2
What vulnerability does CVE-2025-66389 expose in GitHub Copilot?
CVE-2025-66389 exposes GitHub Copilot to unauthorized filesystem access outside of a workspace folder.
3
How can CVE-2025-66389 be mitigated in GitHub Copilot?
Mitigation for CVE-2025-66389 involves restricting the usage of file-handler URI parameters and ensuring user approval before accessing filesystem locations.
4
What potential risks are associated with CVE-2025-66389?
The main risk of CVE-2025-66389 is the potential for exfiltration of sensitive information due to indirect prompt injection.
5
When was CVE-2025-66389 published?
CVE-2025-66389 was published on June 22, 2026.