MediumNewsLLM-specific
GitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets
- Published
- Record updated
Summary
GitHub Copilot CLI can be made to read a developer's local files and send them to an attacker from a single web page. The attack, Cryptographic Context Injection (CCI), hides instructions as ciphertext that the agent decrypts in its own shell and trusts as its own, and the researchers say one attacker-controlled URL fetched in autopilot mode was enough to exfiltrate a .env.prod file in 28 seconds.
Topics
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer