Impact
The vulnerability allows an attacker to supply crafted file paths that escape a restricted directory boundary, enabling access or modification of files outside the sandbox and exposing or altering confidential information on the host system. Based on the description, it is inferred that the attack requires a local attacker who can interact with the extension to provide malicious paths.
Affected Systems
The affected component is the Microsoft Visual Studio Code CoPilot Chat Extension. No specific version information is disclosed; any installation that has not applied the fix is potentially vulnerable. The extension is part of GitHub Copilot and Visual Studio Code.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑impact vulnerability. The EPSS score is below 1%, implying a low but non‑zero exploitation probability. The description indicates that a local attacker is required; exploitation most likely involves manipulating file paths or configuration inputs processed by the extension, after which the attacker can bypass the security feature on the host machine. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment