AI · 4h ago

GitHub Copilot CLI Leaks Secrets Through Encrypted Pages

Adversa AI says GitHub Copilot CLI in autopilot mode can be steered by attacker-controlled web content into exposing secrets. GitHub disputes that framing as a product vulnerability, but the demo shows the agent can be led off the user’s prompt path.

The trick is to hide instructions in encrypted text on a page, then tell the agent to decrypt them and keep going. In the reported chain, Copilot CLI reads a page, follows the decrypt step, pulls local files such as .env data into the key, and then sends the harvested secrets onward as part of the next fetch.

That puts the risk on any agentic tool that can browse, read files, and act on what it finds: the exposure is the workflow, not just the prompt box. If your setup lets the CLI reach local secrets or tokens, the trust boundary now includes fetched content the user did not author.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-07

Editions

Related stories