GitHub Copilot CLI shell tool bypass allows arbitrary code execution (CVE-2026-29783)
GitHub Copilot CLI versions up to and including 0.0.422 contained a flaw where crafted bash parameter expansion patterns could hide executable code inside commands classified as read-only by the safety layer, enabling arbitrary code execution on a user's workstation via prompt injection through repository files, MCP server responses or user instructions. The issue was patched in version 0.0.423.
Disclosed 6 March 2026 · Record updated 13 September 2026
Impact
Attackers able to influence agent commands could bypass the read-only command safety assessment to execute arbitrary code, potentially leading to data exfiltration, file modification or further system compromise.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-29783
