chiprook
← Security
SecurityOctober 6, 2026, 20:00

GitHub Copilot CLI tricked by encrypted web instructions into leaking secrets

Adversa AI demonstrated a Cryptographic Context Injection attack on GitHub Copilot CLI: a malicious web page carries encrypted instructions and a key, and the agent decrypts them itself and sends harvested secrets to the attacker. Microsoft's mai-code-1.1-flash model executed the full chain in 50% of attempts, while OpenAI GPT-5.6 models refused. GitHub declined to treat it as a product vulnerability.

GitHub Copilot CLI tricked by encrypted web instructions into leaking secrets
#GitHub#Copilot#OpenAI#Microsoft
Read next
Security

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI plugins

AI

GitHub Copilot CLI gets HydraFusion multi-model routing

Security

Plugin4Shell: one git trick bypassed safety locks on four AI coding agents

Software

Codex CLI 0.158: approval for elevated commands and MCP OAuth client secrets