GitHub Copilot CLI tricked by encrypted web instructions into leaking secrets
Adversa AI demonstrated a Cryptographic Context Injection attack on GitHub Copilot CLI: a malicious web page carries encrypted instructions and a key, and the agent decrypts them itself and sends harvested secrets to the attacker. Microsoft's mai-code-1.1-flash model executed the full chain in 50% of attempts, while OpenAI GPT-5.6 models refused. GitHub declined to treat it as a product vulnerability.
- The CCI attack works when Copilot CLI runs in autopilot mode
- mai-code-1.1-flash executed the full attack chain in 50% of attempts
- OpenAI GPT-5.6 models refused the malicious payload
- GitHub was notified on September 17, 2026, but rejected the report
Read next
Security