SB2026072884 - OS Command Injection in GitHub Copilot CLI



SB2026072884 - OS Command Injection in GitHub Copilot CLI

Published: July 28, 2026

Security Bulletin ID SB2026072884
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) OS Command Injection (CVE-ID: CVE-2026-29783)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an os command in the shell safety assessment of the shell tool when evaluating crafted bash parameter expansion patterns in command text. A remote attacker can influence commands executed by the agent to execute arbitrary code.

User interaction is required to execute the influenced command.


Remediation

Install update from vendor's website.