PatchSiren cyber security CVE debrief
CVE-2026-29783 Github CVE debrief
CVE-2026-29783 describes an arbitrary code execution issue in the shell tool used by GitHub Copilot CLI. In affected versions prior to and including 0.0.422, crafted bash parameter expansion patterns could make a command appear "read-only" to the safety layer while still embedding executable behavior. GitHub states the issue is fixed in 0.0.423.
- Vendor
- Github
- Product
- Copilot Command Line Interface
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-06
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-03-06
- Advisory updated
- 2026-05-18
Who should care
Organizations and users running GitHub Copilot CLI, especially in workflows where the agent can process untrusted repository content, MCP server responses, or user-supplied instructions. This is most relevant when Copilot CLI is allowed to execute shell commands on a workstation or build environment.
Technical summary
The vulnerability is a command-safety bypass in the shell tool’s pre-execution assessment. According to the source description, the safety layer classifies shell commands as read-only or write-capable, but certain bash parameter expansion forms can hide executable behavior inside otherwise seemingly safe commands. The advisory highlights patterns such as ${var@P}, ${var=value} / ${var:=value}, ${!var}, and nested $(cmd) or <(cmd) within ${...} expansions. This is mapped to CWE-78 and affects GitHub Copilot CLI versions earlier than 0.0.423.
Defensive priority
High. The issue can lead to arbitrary code execution when the agent is influenced by untrusted input, and the reported CVSS score is 7.5 (HIGH).
Recommended defensive actions
- Upgrade GitHub Copilot CLI to version 0.0.423 or later.
- Verify deployed versions and remove or replace any older 0.0.422-and-earlier installations.
- Treat repository content, MCP responses, and prompt text as untrusted inputs when Copilot CLI can execute shell commands.
- Review the GitHub security advisory and release notes for the fixed version before re-enabling broad agent command execution.
Evidence notes
Source material includes the NVD CVE record and GitHub references. The CVE was published on 2026-03-06 and modified on 2026-05-18. NVD lists the vulnerable CPE criteria for github:copilot_command_line_interface as ending before 0.0.423, and the advisory references the fixed release v0.0.423 plus the GitHub security advisory GHSA-g8r9-g2v8-jv6f. The CVSS vector provided by NVD indicates HIGH severity with user interaction required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-29783 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-29783
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-29783 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-29783
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/github/copilot-cli/releases/tag/v0.0.423
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/github/copilot-cli/security/advisories/GHSA-g8r9-g2v8-jv6f
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.