Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Home/CyberSecurity News/Critical GitHub Copilot CLI Bug Exposes Developer Secrets via Prompt Injection
CyberSecurity News

Critical GitHub Copilot CLI Bug Exposes Developer Secrets via Prompt Injection

Key Takeaways A critical prompt injection vulnerability, dubbed Cryptographic Context Injection (CCI), has been identified in GitHub Copilot CLI. The flaw allows an attacker-controlled webpage to...

Marcus Rodriguez
Marcus Rodriguez
October 6, 2026 4 Min Read
2 0

Key Takeaways

  • A critical prompt injection vulnerability, dubbed Cryptographic Context Injection (CCI), has been identified in GitHub Copilot CLI.
  • The flaw allows an attacker-controlled webpage to instruct Copilot CLI to exfiltrate local developer files, such as .env.prod, without explicit user warning.
  • The vulnerability exploits a blind spot in AI security where encrypted malicious instructions bypass conventional prompt injection defenses.
  • While GitHub acknowledged the report, it did not classify it as a security vulnerability, advising users to exercise caution when granting permissions.
  • Organizations are urged to implement strict controls over Copilot CLI’s autonomous browsing and local file access.

A significant security flaw has been discovered in GitHub Copilot CLI, potentially enabling malicious web pages to trick the AI coding assistant into extracting sensitive developer files and transmitting them to external servers. This novel attack technique, termed Cryptographic Context Injection (CCI), leverages encrypted commands to circumvent standard prompt injection safeguards.

Table Of Content

  • Key Takeaways
  • GitHub Copilot CLI Vulnerability Details
  • What You Should Do

According to research conducted by Adversa AI, the vulnerability manifests when Copilot CLI operates in its autopilot mode and is directed by a developer to analyze an external URL. This scenario creates an opening for an attacker to embed hidden instructions that the AI then executes.

GitHub Copilot CLI Vulnerability Details

During a proof-of-concept demonstration, the compromised Copilot CLI agent successfully read a local .env.prod file and transmitted its contents to an attacker-controlled endpoint. This exfiltration occurred within a mere 28 seconds, with no discernible warning or notification provided to the user that a local file had been accessed or its data sent off-device.

The CCI technique builds upon prior research that demonstrated similar vulnerabilities against other AI models, such as Grok. In those instances, encrypted instructions were decrypted within the AI’s runtime environment and subsequently treated as trusted commands. This established a pattern where AI agents could be manipulated into revealing private information through seemingly innocuous web requests.

What differentiates this attack is the method of instruction delivery. Instead of embedding plaintext malicious commands, the attacker’s web page includes encrypted data. It then instructs Copilot CLI to utilize Python to decrypt this data. Traditional static filters, designed to inspect readable content, are ineffective against this method as they do not perform cryptographic operations to reveal hidden text. Once the agent decrypts the content within its own shell environment, researchers note that it may interpret the resulting instructions as originating from a trusted internal process rather than an untrusted external webpage.

The attack chain described involves a deceptive “key” preparation step. One key provided is legitimate, while another is a specially crafted template designed to prompt the agent to read local files before attempting decryption. The initial decryption attempt is intentionally designed to fail, yet this step is sufficient to collect the sensitive file content. Subsequently, the agent uses the valid key, decrypts a second set of instructions, and initiates a web request that includes the previously harvested data.

The researchers warn that this technique is not limited to environment files. Any data accessible to the agent, including but not limited to source code, configuration files, credentials, or tokens located outside the active project folder, could be at risk, provided the agent possesses the necessary read permissions. Earlier research into Copilot’s vulnerabilities has also highlighted how prompt injection can lead to the theft of tokens and sensitive repository data when AI tools process untrusted GitHub content.

Further concerns were raised regarding inconsistent safety behaviors across different models offered through Copilot. Adversa AI reported that Microsoft’s mai-code-1.1-flash model executed the full attack chain in 50% of its tests, whereas two GPT-5.6 models successfully resisted the same instructions. This discrepancy poses a significant risk for users who rely on the “Auto” model selection setting, as routing may direct tasks to different models across sessions without transparently indicating which model processed a given task.

Despite the detailed report, GitHub’s bug bounty team validated the findings but did not categorize them as a security vulnerability. According to the disclosure timeline, GitHub’s stance was that the user had explicitly granted Copilot permission to autonomously fetch attacker-controlled content. The researchers, however, contested this assessment, arguing that the use of encryption effectively bypassed existing protections that would have rejected identical instructions if presented in plaintext.

What You Should Do

  • Restrict Autonomous Browsing: Avoid configuring Copilot CLI to autonomously browse untrusted web pages, especially when it has broad local-file and network permissions.
  • Monitor Agent Activity: Implement robust logging for resolved tool arguments. Be alert to patterns where web content access is immediately followed by code execution and local file reads.
  • Block Unexpected Outbound Destinations: Configure network rules to block unexpected or suspicious outbound network connections initiated by the AI agent.
  • Isolate Sensitive Data: Store sensitive credentials, tokens, and configuration files in locations that are not accessible to the AI agent, ideally outside its active project paths.
  • Review Permissions: Regularly audit and minimize the local file system and network permissions granted to AI coding tools.
  • Focus on Behavioral Monitoring: Recognize that securing AI coding tools requires monitoring the agent’s actual actions and behaviors, not just scanning the text inputs it receives.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Ex-Engineer Jailed for Sabotaging Employer’s Windows Network

Next Post

SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us