Impact
Updated details indicate the vulnerability stems from insufficient restriction of pathnames in the Microsoft Visual Studio Code CoPilot Chat Extension, permitting an attacker to supply crafted file paths that escape the intended directory boundary. This path‑traversal issue, identified as CWE-22, allows unauthorized local file access or modification outside the restricted sandbox, potentially exposing or altering confidential information on the host system.
Affected Systems
The affected component is the Microsoft Visual Studio Code CoPilot Chat Extension. No specific version information is disclosed; any installation that has not applied the fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.4 signals a high‑impact vulnerability. The EPSS score is below 1%, implying a low but non‑zero exploitation probability. The updated description indicates that a local attacker is required, and exploitation most likely involves manipulating file paths or configuration inputs processed by the extension, after which the attacker can bypass the security feature on the host machine. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment