Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:visual_studio_code_copilot_chat_extension:*:*:*:*:*:*:*:* |
Thu, 13 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft github Copilot Chat
|
|
| CPEs | cpe:2.3:a:microsoft:github_copilot_chat:*:*:*:*:*:visual_studio_code:*:* | |
| Vendors & Products |
Microsoft github Copilot Chat
|
Wed, 12 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft visual Studio Microsoft visual Studio Code Copilot Chat Extension |
|
| Vendors & Products |
Microsoft
Microsoft visual Studio Microsoft visual Studio Code Copilot Chat Extension |
Tue, 11 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. | |
| Title | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-13T20:46:16.511Z
Reserved: 2025-10-14T18:24:58.482Z
Link: CVE-2025-62449
Updated: 2025-11-12T14:44:43.650Z
Status : Analyzed
Published: 2025-11-11T18:15:50.043
Modified: 2025-11-13T19:45:11.340
Link: CVE-2025-62449
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:36:49Z