SB2026072884 - OS Command Injection in GitHub Copilot CLI
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) OS Command Injection (CVE-ID: CVE-2026-29783)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an os command in the shell safety assessment of the shell tool when evaluating crafted bash parameter expansion patterns in command text. A remote attacker can influence commands executed by the agent to execute arbitrary code.
User interaction is required to execute the influenced command.
Remediation
Install update from vendor's website.