Incorrect Behavior Order Affecting @github/copilot package, versions <1.0.43


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-GITHUBCOPILOT-16642141
  • published12 May 2026
  • disclosed11 May 2026
  • creditUnknown

Introduced: 11 May 2026

NewCVE-2026-45033  (opens in a new tab)
CWE-696  (opens in a new tab)

How to fix?

Upgrade @github/copilot to version 1.0.43 or higher.

Overview

@github/copilot is a GitHub Copilot CLI brings the power of Copilot coding agent directly to your terminal.

Affected versions of this package are vulnerable to Incorrect Behavior Order that enables code execution via the core.fsmonitor configuration key in a nested bare git repository. An attacker can execute commands by placing a malicious bare repository within a project directory and forcing or convincing a user to perform agent operations on the project, which automatically discovers and processes the bare repository during git operations such as status or diff.

References

CVSS Base Scores

version 4.0
version 3.1