Incorrect behavior order in GitHub Copilot CLI - CVE-2026-45033
Published: July 28, 2026
GitHub Copilot CLI
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to incorrect behavior order in git operations when processing a project directory containing a nested bare git repository with executable configuration keys. A remote attacker can place a malicious bare repository inside a project to execute arbitrary commands.
User interaction is required in that GitHub Copilot CLI must perform git operations in or near the malicious directory.