High
nvd
·
CVE-2025-66389
CVE-2025-66389: GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler
Published Jun 22, 2026
CVSS 7.5
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Affected AI Products
prompt injection
indirect prompt
github copilot
copilot