Cyber Security

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide the coding agent into reading local developer files and sending their contents to a remote server.

The technique, called Cryptographic Context Injection (CCI), hides malicious instructions in encrypted text, making them harder for normal prompt-injection checks to inspect.

According to Adversa AI, the issue affects Copilot CLI when it is running in autopilot mode, and a developer asks the agent to review an external URL.

GitHub Copilot CLI Vulnerability

In a demonstration, the agent reportedly read a local .env.prod file and transmitted its contents to an attacker-controlled endpoint within 28 seconds. The user received no clear warning that a local file had been accessed or that its data had left the device.

The finding builds on CCI research previously demonstrated against Grok, where encrypted instructions were decrypted inside an AI runtime and then treated as trusted output. Cyber Security News previously covered that research, which showed how an AI agent could be tricked into exposing private chat information through an ordinary web-page request.

In this case, the malicious page does not expose its real instructions as normal text. Instead, it includes encrypted data and tells Copilot CLI to use Python to decrypt it.

Static filters can inspect readable content, but they do not normally run cryptographic operations to reveal hidden text. Once the agent decrypts the content in its own shell environment, the researchers said it may treat the resulting instructions as if they came from a trusted internal process rather than an untrusted webpage.

The reported chain uses a deceptive “key” preparation step. One supplied key is genuine, while another is a template that causes the agent to read local files before attempting decryption. The first decryption attempt fails by design, but the sensitive file content has already been collected. The agent then uses the valid key, decrypts a second instruction set, and makes a web request containing the harvested data.

Researchers said the technique could target more than environment files. Any data accessible to the agent, including source code, configuration files, credentials, or tokens outside the active project folder, could be at risk if the agent has permission to read it. Earlier Copilot-related research has also shown how prompt injection can be used to steal tokens and sensitive repository data when AI tools process untrusted GitHub content.

The report also highlighted inconsistent safety behavior between models offered through Copilot. Adversa AI claimed that Microsoft’s mai-code-1.1-flash executed the full chain in half of its tests, while two GPT-5.6 models refused the same instructions. This introduces a major concern for users who leave model selection on Auto, since routing may select different models across sessions without clearly showing which model processed a task.

GitHub’s bug bounty team reportedly validated the report but did not classify it as a security vulnerability. According to the disclosure timeline, the company’s position was that the user had explicitly granted Copilot permission to autonomously fetch attacker-controlled content. The researchers disagreed, arguing that encryption bypassed protections that rejected the same instructions in plaintext.

Organizations using Copilot CLI should avoid allowing autonomous agents to browse untrusted pages with broad local-file and network permissions.

Security teams should log resolved tool arguments, alert when web content is followed by code execution and local-file reads, and block unexpected outbound destinations. Keep sensitive credentials outside agent-readable paths wherever possible. This case shows that securing AI coding tools requires watching what the agent actually does, not only scanning the text it receives.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

2 minutes ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

7 minutes ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

47 minutes ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

54 minutes ago

Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure

Iranian state-aligned hackers have used a fake Dubai Airports recruitment process to target Iraqi critical…

1 hour ago

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

Torrance, Californina, October 6th, 2026, CyberNewswire Criminal IP by AI SPERA, a cyber threat intelligence…

2 hours ago