A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide the coding agent into reading local developer files and sending their contents to a remote server. The technique, called Cryptographic Context Injection (CCI), hides malicious instructions in encrypted text, making them harder for normal prompt-injection... Weiterlesen: GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secre…
Intelligence View
⚡ tsecurity.de Intelligence
GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection
A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide the coding agent into reading local developer files and sending…