Encrypted pages can steer GitHub Copilot CLI into leaking secrets
Adversa AI says crafted pages can make GitHub Copilot CLI decrypt hidden instructions and exfiltrate local developer secrets.
Adversa AI reported on 17 September 2026 that GitHub Copilot CLI in autopilot mode can be steered by Cryptographic Context Injection on a crafted page, with public coverage on 6–7 October 2026. The page supplies ciphertext and key material and asks the agent to decrypt it in Python so plaintext filters never see the instructions; The Register described a fake key that prompts reads of files such as .env, then a second key that reveals exfiltration instructions, while Cyber Security News, GBHackers, and CSO Online said a demo read .env.prod and sent it to an attacker endpoint in 28 seconds, with CSO adding that the destination was not named and that decrypted text was then treated as trusted context. Microsoft’s mai-code-1.1-flash completed the chain on about half of attempts, two OpenAI GPT-5.6 models refused, and The Register said Auto routing can select either model without showing the user which ran. GitHub validated the September report but rejected it as a product vulnerability and, according to GBHackers and CSO, as bounty-eligible; outlets disagree on the rationale, citing required user confirmation, permission for autonomous fetches of untrusted content, or both. GBHackers said the chain was still reproducible on 1 October 2026, that payloads were withheld, and that tighter agent controls were recommended.
- Adversa AI reported Cryptographic Context Injection against GitHub Copilot CLI on 17 September 2026; public write-ups appeared on 6–7 October 2026.
- In autopilot mode, a fetched page supplies encrypted instructions and key material and asks the agent to decrypt them in Python, so plaintext-only filters do not see the hidden commands.
- The Register: a fake key template leads the agent to read local files such as .env; a second key then reveals instructions to send harvested secrets to an attacker URL.
- Cyber Security News, GBHackers, and CSO Online: a demonstration read .env.prod and sent it to an attacker endpoint in 28 seconds; CSO said the destination was not named.
- Microsoft’s mai-code-1.1-flash completed the chain on about half of attempts; two OpenAI GPT-5.6 models refused. The Register said Auto routing can select either model without showing the user which ran.
- GitHub validated the report but rejected it as a product vulnerability and, per GBHackers and CSO, as bounty-eligible. Sources disagree whether the reason was required user confirmation, permission for autonomous fetches of untrusted…
- GBHackers: the chain was still reproducible on 1 October 2026, payloads were withheld, and tighter agent controls were recommended.
Coverage timelineoldest first · each row is one article
- · 2d agoZombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
The Register · Security· 67
Researchers say crafted web pages can make GitHub Copilot CLI decrypt hidden instructions and leak secrets.
- · 2d agoGitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection
Cyber Security News· 66
Encrypted prompt injection can steer GitHub Copilot CLI in autopilot mode to steal local developer secrets.
- · 1d ago