Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Security Research

This repository documents publicly disclosed security vulnerabilities that I responsibly reported to software vendors.

No exploit code or proof-of-concept code is included in this repository.

Each advisory linked below publicly acknowledges me (Daniel Weglowski) as the reporter.

Some advisory pages may prevent automated systems from accessing the acknowledgement section. Where available, machine-readable CSAF advisories are also provided.


CVE-2026-70335

Summary

CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

  • Reported to Microsoft Security Response Center (MSRC)
  • Impact: Elevation of Privilege
  • Severity (CVSS v3.1): 7.8/10 (High severity)
  • Acknowledged by Microsoft: August 2026

Acknowledgements

The official MSRC advisory acknowledges:

Daniel Weglowski
Tarek Nakkouch

Public advisories


CVE-2026-45482

Summary

CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

  • Reported to Microsoft Security Response Center (MSRC)
  • Impact: Security Feature Bypass
  • Severity (CVSS v3.1): 8.4/10 (High severity)
  • User Interaction: None (UI:N)
  • Acknowledged by Microsoft: June 2026

Acknowledgements

The official MSRC advisory acknowledges:

Daniel Weglowski

Public advisories


CVE-2025-29822

Summary

CVE-2025-29822 Microsoft OneNote Security Feature Bypass Vulnerability

  • Reported to Microsoft Security Response Center (MSRC)
  • Impact: Security Feature Bypass
  • Severity (CVSS v3.1): 7.8/10 (High severity)
  • Acknowledged by Microsoft: April 2025

Acknowledgements

The official MSRC advisory acknowledges:

Daniel Weglowski

Public advisories


CVE-2023-36436

Summary

CVE-2023-36436 Windows MSHTML Platform Remote Code Execution Vulnerability

  • Reported to Microsoft Security Response Center (MSRC)
  • Impact: Remote Code Execution
  • Severity (CVSS v3.1): 7.8/10 (High severity)
  • Acknowledged by Microsoft: November 2023

Acknowledgements

The official MSRC advisory acknowledges:

Daniel Weglowski

Public advisories

About

Public references for security vulnerabilities responsibly reported by Daniel Weglowski, including official MSRC acknowledgements and CSAF advisories.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors