Incorrect behavior order in GitHub Copilot CLI - CVE-2026-45033
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to incorrect behavior order in git operations when processing a project directory containing a nested bare git repository with executable configuration keys. A remote attacker can place a malicious bare repository inside a project to execute arbitrary commands.
User interaction is required in that GitHub Copilot CLI must perform git operations in or near the malicious directory.
Affected software
Bob
How to mitigate CVE-2026-45033
Bob - update to 2.0