CVE-2026-45482: Path traversal in GitHub Copilot and Visual Studio Code
A path traversal flaw (CVE-2026-45482) in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Microsoft published an advisory for the issue in its update guide.
Disclosed 9 June 2026 · Record updated 13 September 2026
Impact
Local bypass of a security feature via improper limitation of a pathname to a restricted directory.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45482
