github / github/copilot-cli

Copilot CLI might misinterprets container paths in docker compose exec as host filesystem access

Open
#2,244 0 comments 0 reactions 0 assignees View on GitHub
area:permissions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

When Copilot CLI proposes or runs a command that accesses a path inside a Docker container, it appears to treat that path as if it were a local host path and triggers a directory access approval prompt for it.

`docker compose exec ls /some/container/path/file`
triggers a permission prompt claiming that /some/container/path/file is outside the allowed local directories. And asks if it should default allow it. Here im unsere what this will mean and in what context this will be added.

Otherwise thanks a lot for the great product!

### Affected version

GitHub Copilot CLI 1.0.11

### Steps to reproduce the behavior

- start copilot without any arguments
- copilot suggest to do something with docker exec with a /path/to/somewhere

### Expected behavior

_No response_

### Additional context

_No response_

Contributor guide

Open the contributing guide

Research direction

Reproduce from the copilot entry point with no arguments using docker compose exec ls /some/container/path/file, and observe the directory-access approval prompt. Trace how the CLI classifies paths in that command; done means container paths are not treated as local host paths while genuine host access still receives the appropriate prompt.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker-compose, shell
Domain
cli, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.