CVE-2026-50510
HIGHDescription
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
Is your site exposed to CVE-2026-50510?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-50510? +
How severe is CVE-2026-50510? +
How do I check if I'm vulnerable to CVE-2026-50510? +
Related Vulnerabilities
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Office OneNote Remote Code Execution Vulnerability
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing …
Windows Distributed File System (DFS) Remote Code Execution Vulnerability