CVE-2025-66389: GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a...
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
Security readout for executives and security teams
Plain-English summary
GitHub Copilot 1.372.0 is reported to allow filesystem access outside the workspace through a file-handler URI used by fetch_webpage. If Copilot processes hostile indirect prompt-injection content, sensitive local files could be exposed. The source bundle does not identify a patch, broader affected versions, or active exploitation.
Executive priority
Prioritize this for developer environments handling secrets, source code, or customer data. The main business risk is local confidential data exposure from trusted AI tooling. Urgency is high, but final remediation should follow vendor confirmation because fix details are not in the bundle.
Technical view
The CVE describes CWE-552 exposure: fetch_webpage can be influenced with a file-handler URI parameter to access files beyond the intended workspace boundary without user approval. CVSS 3.1 is 7.5, driven by confidentiality impact. Integrity and availability impact are not reported.
Likely exposure
Organizations using GitHub Copilot 1.372.0 or related VS Code Copilot Chat functionality may be exposed. The CVE record’s structured affected-product fields are incomplete, so teams should verify exact extension and editor versions against vendor guidance.
Exploitation context
The bundle says exfiltration could occur if indirect prompt injection is involved. KEV is false, and no provided source confirms active exploitation in the wild. Treat exploit status as unconfirmed, not absent.
Researcher notes
The record ties the issue to a file-handler URI parameter in fetch_webpage and references VS Code Copilot Chat source plus a public blog. Affected-product metadata is weak, so validation should focus on reproducing scope boundaries defensively and confirming vendor-fixed builds.
Mitigation direction
Check Microsoft or GitHub guidance for fixed versions or configuration mitigations.
Inventory developer workstations using GitHub Copilot 1.372.0.
Update Copilot and VS Code components when vendor fixes are available.
Limit Copilot exposure to untrusted webpages, repositories, or generated content until assessed.
Review data-loss controls for sensitive files on developer endpoints.
Validation and detection
Confirm installed GitHub Copilot and Copilot Chat versions on developer endpoints.
Review whether fetch_webpage or similar web-fetch tooling is enabled.
Check vendor advisories for affected-version and fixed-version statements.
Look for endpoint alerts involving unusual local file reads by editor processes.
Assess whether developers use Copilot against untrusted content sources.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-552: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-552 · source CWE mapping
Files or Directories Accessible to External Parties
Files or Directories Accessible to External Parties represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.