Threat · curated 6 Oct 2026
GitHub Copilot CLI vulnerability leaks developer secrets
First reported adversa.ai
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Cryptographic Context Injection turns a routine 'go read this URL' request into silent secret theft on a widely deployed coding agent, bypassing text-based guardrails by forcing malicious instructions through the agent's own code-execution runtime.
Adversa AI researchers demonstrated Cryptographic Context Injection (CCI) against GitHub Copilot CLI: a single attacker-controlled web page delivers encrypted instructions plus a key and a decrypt command, and when the agent runs in autopilot mode it decrypts the ciphertext in its own shell, trusts the plaintext as its own instructions, and exfiltrates local secrets (e.g. .env.prod files) to an attacker endpoint. Because the payload is ciphertext, static content classifiers miss it, and the chain only runs on one of the models offered via Copilot's opaque Auto routing. GitHub's bug bounty team validated the finding but declined to treat it as a vulnerability, and it still reproduced as of October 1, 2026.