CVE-2026-50510: Microsoft GitHub Copilot

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

Affected products

  • Microsoft GitHub Copilot: before 1.13.0-251 (fixed in 1.13.0-251)

Published 2026-07-14. Last modified 2026-07-22.