Microsoft: GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

Microsoft: GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

GitHub Copilot CLI Vulnerability Exposes Local Files via Encrypted Attack Technique

Researchers at Adversa AI have uncovered a novel attack method targeting GitHub Copilot CLI, enabling threat actors to exfiltrate local developer files by exploiting a technique called Cryptographic Context Injection (CCI). The vulnerability affects Copilot CLI when running in autopilot mode, particularly if a developer instructs the agent to review an external URL.

In a proof-of-concept demonstration, the agent accessed a local .env.prod file and transmitted its contents to an attacker-controlled server within 28 seconds without triggering any visible warnings for the user. The attack leverages encrypted instructions embedded in a malicious webpage, bypassing traditional prompt-injection detection by concealing the payload until decryption occurs within the AI’s runtime.

The exploit chain involves a deceptive decryption process: A fake key is used to trick the agent into reading local files before a second, valid key decrypts instructions to exfiltrate the stolen data. While the first decryption fails by design, the sensitive data is already harvested. Researchers warn that the technique could target any accessible files, including source code, credentials, or configuration files, provided the agent has read permissions.

Model behavior inconsistencies further complicate the issue. Tests revealed that Microsoft’s mai-code-1.1-flash executed the attack in 50% of cases, while two GPT-5.6 models refused the same instructions. This variability poses risks for users relying on auto-model selection, as different sessions may process tasks with varying security postures.

GitHub’s bug bounty team acknowledged the report but did not classify it as a security vulnerability, arguing that users explicitly grant Copilot permission to fetch untrusted content. However, researchers countered that the encryption-based bypass circumvents protections that would block the same instructions in plaintext.

The findings underscore the need for enhanced monitoring of AI coding tools, including logging tool arguments, detecting suspicious sequences (e.g., web content followed by file reads and network requests), and restricting outbound connections. Organizations are advised to limit agent permissions and store sensitive credentials outside agent-accessible paths.

Source: https://cybersecuritynews.com/github-copilot-cli-vulnerability/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft

"id": "mic1791303903",
"linkid": "microsoft",
"type": "Vulnerability",
"date": "10/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Developers using GitHub Copilot '
                                              'CLI in autopilot mode',
                        'industry': 'Software Development / AI',
                        'name': 'GitHub (Microsoft)',
                        'size': 'Large',
                        'type': 'Technology Company'}],
 'attack_vector': 'Malicious URL via AI Agent (Copilot CLI)',
 'customer_advisories': 'Developers should avoid instructing Copilot CLI to '
                        'review untrusted URLs and limit agent access to '
                        'sensitive files.',
 'data_breach': {'data_encryption': 'No (data was exfiltrated in plaintext '
                                    'after decryption)',
                 'data_exfiltration': 'Yes (transmitted to attacker-controlled '
                                      'server)',
                 'file_types_exposed': ['.env.prod',
                                        'Source code files',
                                        'Configuration files'],
                 'personally_identifiable_information': 'Possible (if stored '
                                                        'in accessible files)',
                 'sensitivity_of_data': 'High (e.g., .env.prod files, PII, '
                                        'credentials)',
                 'type_of_data_compromised': ['Credentials',
                                              'Configuration files',
                                              'Source code']},
 'description': 'Researchers at Adversa AI uncovered a novel attack method '
                'targeting GitHub Copilot CLI, enabling threat actors to '
                'exfiltrate local developer files by exploiting a technique '
                'called Cryptographic Context Injection (CCI). The '
                'vulnerability affects Copilot CLI when running in autopilot '
                'mode, particularly if a developer instructs the agent to '
                'review an external URL. The attack leverages encrypted '
                'instructions embedded in a malicious webpage, bypassing '
                'traditional prompt-injection detection by concealing the '
                'payload until decryption occurs within the AI’s runtime.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'GitHub/Copilot',
            'data_compromised': 'Local files (.env.prod, source code, '
                                'credentials, configuration files)',
            'identity_theft_risk': 'High (if credentials or PII are exposed)',
            'operational_impact': 'Potential unauthorized access to sensitive '
                                  'files',
            'systems_affected': 'GitHub Copilot CLI (autopilot mode)'},
 'initial_access_broker': {'entry_point': 'Malicious URL processed by Copilot '
                                          'CLI',
                           'high_value_targets': 'Local files (.env.prod, '
                                                 'credentials, source code)'},
 'investigation_status': 'Acknowledged by GitHub (not classified as a security '
                         'vulnerability)',
 'lessons_learned': 'The incident highlights the risks of AI agents processing '
                    'untrusted content, the need for enhanced monitoring of AI '
                    'tool behavior, and the importance of restricting agent '
                    'permissions to sensitive files.',
 'motivation': 'Demonstration of AI Agent Exploitation',
 'post_incident_analysis': {'corrective_actions': ['Improve detection of '
                                                   'encrypted malicious '
                                                   'instructions',
                                                   'Enforce stricter '
                                                   'permissions for AI agents',
                                                   'Enhance monitoring and '
                                                   'logging of agent '
                                                   'activities'],
                            'root_causes': ["Copilot CLI's autopilot mode "
                                            'processing untrusted external '
                                            'content',
                                            'Encrypted payloads bypassing '
                                            'prompt-injection detection',
                                            'Inconsistent security postures '
                                            'across AI models (e.g., '
                                            'mai-code-1.1-flash vs. GPT-5.6)']},
 'recommendations': ['Limit agent permissions to sensitive files and '
                     'directories',
                     'Store credentials outside agent-accessible paths',
                     'Implement enhanced monitoring for suspicious sequences '
                     '(e.g., web content followed by file reads and network '
                     'requests)',
                     'Restrict outbound connections from AI agents',
                     'Improve detection of encrypted malicious payloads in AI '
                     'inputs'],
 'references': [{'source': 'Adversa AI Research'}],
 'response': {'enhanced_monitoring': 'Recommended (logging tool arguments, '
                                     'detecting suspicious sequences)'},
 'stakeholder_advisories': 'Organizations using GitHub Copilot CLI should '
                           'review agent permissions and implement recommended '
                           'security measures.',
 'threat_actor': 'Adversa AI Researchers (Proof-of-Concept)',
 'title': 'GitHub Copilot CLI Vulnerability Exposes Local Files via '
          'Cryptographic Context Injection',
 'type': 'Data Exfiltration',
 'vulnerability_exploited': 'Cryptographic Context Injection (CCI)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.