Researchers successfully made GitHub Copilot CLI read sensitive local files and send their contents to an external endpoint.
Progress disclosed a critical command injection flaw that lets malicious OpenAPI or Swagger documents execute OS commands.