{"data":{"id":"870e5777-95bb-416e-8630-2cc83619a9b5","title":"GitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets","summary":"GitHub Copilot CLI can be made to read a developer's local files and send them to an attacker from a single web page. The attack, Cryptographic Context Injection (CCI), hides instructions as ciphertext that the agent decrypts in its own shell and trusts as its own, and the researchers say one attacker-controlled URL fetched in autopilot mode was enough to exfiltrate a .env.prod file in 28 seconds.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://adversa.ai/blog/cryptographic-context-injection-github-copilot/","publishedAt":"2026-10-06T12:50:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["prompt_injection","data_extraction"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["GitHub Copilot CLI","GitHub Copilot","Cryptographic Context Injection"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-06T12:50:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}