Security Advisory

CVE-2025-59252

9.3
CRITICAL

Vulnerability Description

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
Published Date October 9, 2025
Official Source NIST NVD Advisory