Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

GitHub Copilot Chat Flaw Leaks Repo Data

October 10, 2025
Reading Time: 3 mins read
in Incidents
Microsoft 365 Outage Hits Services

A security vulnerability was recently discovered in GitHub Copilot Chat, an AI assistant designed to help developers with coding tasks. The flaw, detailed by security firm Legit Security, allowed a researcher to gain full control over Copilot’s responses and even leak sensitive information from users’ private repositories. This was achieved by using a technique called remote prompt injection alongside a creative bypass of GitHub’s Content Security Policy (CSP).

The vulnerability stemmed from a feature that allows users to hide content from the rendered Markdown using HTML comments. While the comments themselves were hidden, the text was still processed by the AI. A researcher named Omer Mayraz from Legit Security discovered he could inject commands and instructions into these hidden comments. When other users interacted with the AI, the hidden instructions were processed as part of their chat context. This allowed the attacker to manipulate Copilot’s suggestions, potentially tricking other users into installing malicious packages.

To escalate the attack, Mayraz realized he could craft prompts that instructed Copilot to access a user’s private repository, encode its content, and append it to a URL. The goal was to have the user click the URL, which would then exfiltrate the stolen data. However, GitHub’s CSP blocks external requests from untrusted domains, preventing this type of data leakage. Specifically, any HTML image tags injected into the chat would be blocked unless the URL was first validated and proxied through GitHub’s Camo service.

Mayraz found a way to bypass this protection. GitHub’s Camo proxy is designed to fetch external images from a secure, controlled source. To get around this, Mayraz pre-generated a dictionary of valid Camo URLs for every letter and symbol in the alphabet. By embedding this dictionary into his injected prompt, he could instruct Copilot to construct valid Camo URLs on the fly to exfiltrate the stolen data. This allowed him to retrieve the encoded repository content one character at a time.

To prove the exploit’s effectiveness, Mayraz demonstrated how the attack could be used to leak sensitive data like AWS keys and zero-day vulnerabilities. GitHub was notified of the issue and has since patched the vulnerability by disallowing the use of the Camo service to leak sensitive user information. This discovery highlights the ongoing security challenges of AI-powered tools and the importance of addressing vulnerabilities that could lead to data theft and manipulation.

Reference:

  • GitHub Copilot Chat Flaw Leaked Private Repo Data Across Multiple Orgs And Users
Tags: cyber incidentsCyber Incidents 2025Cyber threatsOctober 2025
ADVERTISEMENT

Related Posts

Belgian Telecoms Hit By Cyberattack

Hackers Steal Data From Swiss Bank

November 6, 2025
Belgian Telecoms Hit By Cyberattack

Belgian Telecoms Hit By Cyberattack

November 6, 2025
Belgian Telecoms Hit By Cyberattack

Sandworm Wipers Hit Ukraines Grain Hub

November 6, 2025

Hackers Target UK Water Suppliers

November 5, 2025

Nikkei Data Breach Hits 17000

November 5, 2025
Microsoft Edge Adds Scareware Sensor

Apache OpenOffice Denies Breach

November 5, 2025

Latest Alerts

Russia Group Exploits Windows HyperV

SkyCloak Backdoor Targets Defense Firms

Teams Bugs Let Hackers Impersonate

Post SMTP Plugin Hijacks Admins

React Native CLI Flaw Exposed

Smudged Serpent Targets US Experts

Subscribe to our newsletter

    Latest Incidents

    Hackers Steal Data From Swiss Bank

    Belgian Telecoms Hit By Cyberattack

    Sandworm Wipers Hit Ukraines Grain Hub

    Hackers Target UK Water Suppliers

    Nikkei Data Breach Hits 17000

    Apache OpenOffice Denies Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial