Skip to content
MediumNewsLLM-specific

GitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets

Published
Record updated
View JSON

Summary

GitHub Copilot CLI can be made to read a developer's local files and send them to an attacker from a single web page. The attack, Cryptographic Context Injection (CCI), hides instructions as ciphertext that the agent decrypts in its own shell and trusts as its own, and the researchers say one attacker-controlled URL fetched in autopilot mode was enough to exfiltrate a .env.prod file in 28 seconds.