365_copilot_chat vulnerabilities
CVEs whose affected-version data names the 365_copilot_chat package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-78501High· 7.4Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
▾ Twilightmicrosoft · 365_copilot_chatEPSS 0.89%via NVD
CVE-2025-59286Critical· 9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
▾ Midnightmicrosoft · 365_copilot_chatEPSS 0.57%via NVD
CVE-2025-59272Critical· 9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
▾ Midnightmicrosoft · 365_copilot_chatEPSS 0.57%via NVD