Encrypted instructions make Copilot CLI leak secrets
🔐 Security researchers at Adversa AI disclosed a technique called Cryptographic Context Injection (CCI) that embeds malicious instructions inside encrypted content to influence GitHub Copilot CLI. When Copilot decrypts and executes that content in autopilot mode, it can be tricked into reading local secret files and exfiltrating them to an attacker-controlled endpoint. GitHub validated the behavior but declined to classify it as a vulnerability, citing user authorization and autonomous mode, while Adversa disputes that assessment.
