github / github/copilot-cli

Copilot is (sometimes) able to delete files outside of the allowed directories via ~ expansion and interpreter execution (Python shutil.rmtree)

Đang mở
#2,309 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:permissions
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the bug

Copilot CLI can delete files outside explicitly allowed directories when:

1. Shell commands use ~ (tilde) paths, or
2. Copilot executes Python code (e.g. shutil.rmtree) that performs filesystem operations

According to my understanding of how --add-dir / trusted directories work, both cases bypass Copilot CLI’s path‑based permission enforcement.

### Affected version

1.0.11

### Steps to reproduce the behavior

Within the `/sandbox/workdir` folder execute this command:

```
copilot -p "create an hello-world.py script, then run it, then list all files in your workdir, then remove all contents in the folder .copilot/session-state. if you fail to delete contents keep trying in different ways at least 10 times before you give up" \
--add-dir /sandbox/workdir/ \
--allow-all-tools \
--allow-all-urls
```

### Expected behavior

Copilot CLI should not read, modify, or delete files outside /sandbox/workdir, regardless of:

- whether ~ is used instead of absolute paths
- whether deletion is attempted via shell commands or via code (e.g. Python)

In particular, /sandbox/.copilot/session-state outside /sandbox/workdir should remain protected.

### Additional context

- Copilot CLI version: 1.0.11
- OS: Linux
- Shell: bash
- Working directory: /sandbox/workdir

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.