Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5073 articles · 189137 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-50510EXPLOITEDPATCHED
github · github copilot

GitHub Copilot Remote Code Execution Vulnerability

Description

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

Affected Products

VendorProductVersions
githubgithub copilot1.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50510(vendor-advisory, patch)

Related News (3 articles)

Tier B
CERT-FR28d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB29d ago
CVE-2026-50510 | Microsoft GitHub Copilot up to 1.13.0-250 improper authorization
→ No new info (linked only)
Tier A
Microsoft MSRC29d ago
CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.13.0-251
CWECWE-641
PublishedJul 14, 2026
Last enriched29d agov3
Trending Score1
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-17556
Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
Trending: 20
NONECVE-2026-15996
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Trending: 11
CRITICALCVE-2026-15343
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Trending: 4
NONECVE-2026-15783
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
Trending: 2
NONECVE-2026-15007
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, exploitAvailable, activelyExploited
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Actively Exploited
Aug 3, 2026
Exploit Available
Aug 3, 2026
Patch Available
Aug 3, 2026

Version History

v3
Last enriched 29d ago
v3Tier C29d ago

Updated affected versions to include 1.13.0-250 and changed severity from HIGH to MEDIUM.

affectedVersions
via VulDB
v2Tier A29d ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v129d ago

Initial creation