CVE-2026-45482: Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Metrics
- CVSS v3.1
- 8.4
- Severity
- HIGH
- Fixed in
- 1.123.2
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A path traversal vulnerability in the GitHub Copilot Chat extension for Visual Studio Code allows a local attacker to bypass security restrictions without any credentials. The attack is launched locally on the host and requires no user interaction or privileges, derived from the CVSS vector (AV:L, PR:N, UI:N). Successful exploitation grants the attacker full read access, write access, and the ability to disrupt the affected service on the compromised host. A patched-image rebuild at version 1.123.2 is available on HarborGuard for environments running an affected version of the extension.
HarborGuard Coverage
Detection of CVE-2026-45482 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle the Copilot Chat extension. Any image shipping the affected extension version range (0.27.0 to below 1.123.2) is flagged automatically.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.4 (HIGH) and weighting it against each environment's compliance policy to surface appropriate urgency. Triage routing to the right team inbox within each customer organization is available automatically on match.
AvailableA patched-image rebuild at version 1.123.2 is available on HarborGuard for any image found to carry an affected version of the Copilot Chat extension. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host; no network-facing exposure is required.
- AuthenticationNot required
No credentials or account are required to launch the attack.
- Victim interactionNot required
No user action or social engineering is needed; the attacker can exploit the flaw without any victim participation.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special conditions, race requirements, or environmental dependencies on the attacker.
Blast Radius
- A successful attacker reads files outside the intended restricted directory, including configuration files, stored tokens, or extension data on the host.
- The attacker writes or overwrites files in arbitrary paths on the host filesystem, enabling persistent modification of application or system files.
- The attacker disrupts the Copilot Chat extension or dependent processes, causing service failure on the affected workstation.
- Because all three CVSS impact dimensions are HIGH, the attacker gains effective full-impact control over the confidentiality, integrity, and availability of resources accessible to the extension process.
How HarborGuard Handles This
Available on HarborGuard: detection of CVE-2026-45482 is active the moment the CVE enters upstream advisory feeds, and any customer image bundling the Copilot Chat extension at a version below 1.123.2 (from 0.27.0) is flagged in the relevant registry or pipeline scan. For customers who opt into auto-remediation, HarborGuard can rebuild the image at the patched version 1.123.2, execute a regression test run against the rebuilt image, and open a pull request against affected workloads. Where compliance policy permits this flow, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the rebuilt image at 1.123.2 is available for manual promotion through the standard promotion workflow.
Fix available
- Microsoft / Microsoft Visual Studio Code CoPilot Chat Extension< 1.123.2 (from 0.27.0)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C