Impact
GitHub Copilot 1.372.0 contains a flaw that permits the fetch_webpage tool to read files outside the designated workspace using a file-handler URI parameter. This bypasses user approval and could enable an attacker to exfiltrate sensitive files if indirect prompt injection is achieved.
Affected Systems
The vulnerability affects the GitHub Copilot extension, specifically version 1.372.0. The product is distributed by GitHub (Microsoft).
Risk and Exploitability
Although the CVSS score is not provided, the lack of user confirmation required for file access suggests a high impact. The exploit requires that an attacker can influence the Copilot input – for example through an indirect prompt injection scenario. With no EPSS data and no listing in CISA KEV, the current exploitation risk is uncertain but the potential consequences warrant prompt action.
OpenCVE Enrichment