HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-45482Published Modified CNA microsoft

CVE-2026-45482: Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Metrics

CVSS v3.1
8.4
Severity
HIGH
Fixed in
1.123.2
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A path traversal vulnerability in the GitHub Copilot Chat extension for Visual Studio Code allows a local attacker to bypass security restrictions without any credentials. The attack is launched locally on the host and requires no user interaction or privileges, derived from the CVSS vector (AV:L, PR:N, UI:N). Successful exploitation grants the attacker full read access, write access, and the ability to disrupt the affected service on the compromised host. A patched-image rebuild at version 1.123.2 is available on HarborGuard for environments running an affected version of the extension.

HarborGuard Coverage

Detection

Detection of CVE-2026-45482 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle the Copilot Chat extension. Any image shipping the affected extension version range (0.27.0 to below 1.123.2) is flagged automatically.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.4 (HIGH) and weighting it against each environment's compliance policy to surface appropriate urgency. Triage routing to the right team inbox within each customer organization is available automatically on match.

Available
Patch

A patched-image rebuild at version 1.123.2 is available on HarborGuard for any image found to carry an affected version of the Copilot Chat extension. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; no network-facing exposure is required.

  • AuthenticationNot required

    No credentials or account are required to launch the attack.

  • Victim interactionNot required

    No user action or social engineering is needed; the attacker can exploit the flaw without any victim participation.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no special conditions, race requirements, or environmental dependencies on the attacker.

Blast Radius

  • A successful attacker reads files outside the intended restricted directory, including configuration files, stored tokens, or extension data on the host.
  • The attacker writes or overwrites files in arbitrary paths on the host filesystem, enabling persistent modification of application or system files.
  • The attacker disrupts the Copilot Chat extension or dependent processes, causing service failure on the affected workstation.
  • Because all three CVSS impact dimensions are HIGH, the attacker gains effective full-impact control over the confidentiality, integrity, and availability of resources accessible to the extension process.

How HarborGuard Handles This

Available on HarborGuard: detection of CVE-2026-45482 is active the moment the CVE enters upstream advisory feeds, and any customer image bundling the Copilot Chat extension at a version below 1.123.2 (from 0.27.0) is flagged in the relevant registry or pipeline scan. For customers who opt into auto-remediation, HarborGuard can rebuild the image at the patched version 1.123.2, execute a regression test run against the rebuilt image, and open a pull request against affected workloads. Where compliance policy permits this flow, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the rebuilt image at 1.123.2 is available for manual promotion through the standard promotion workflow.

See how HarborGuard automates this
Affected packages
  • Microsoft / Microsoft Visual Studio Code CoPilot Chat Extension
    < 1.123.2 (from 0.27.0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C