
GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model.
The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function.
This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection (CCI).
Imagine a GitHub Copilot CLI user is working on a project and running the agent in autopilot mode. In other agentic coding tools like Anthropic's Claude, that's the default, but it remains optional for GitHub Copilot CLI.
Given that condition, the next requirement is for the CLI tool to read a web page with a malicious set of instructions that have been encrypted with a private key published on the same site.
"Static guardrails read text; they do not run it," explained Rony Utevsky in a blog post provided to . "CCI ships malicious instructions as strong ciphertext, along with the key material and an instruction to decrypt, and induces the agent to run that decryption in its own code execution runtime."
Active content classifiers that might be reading ingested text as a model defense would miss the encrypted code, unlike encodings like base64 or substitution ciphers that can be undone because the model learned how to decode in training.
The model lottery
The attack chain goes like this: The user runs Copilot CLI and asks it to fetch a specific URL. The page contains encrypted content, decryption instructions calling for use of Python, and two possible decryption keys.
The first key is fake. It's a template that the agent tries to build by reading targeted files from disk (e.g., the user's .env file). Those secrets then get added to the key string. The initial decryption is attempted with this phony key but fails.
So the second key is tried, the decryption works, and the agent is presented with instructions to fetch another URL for more context – but that URL contains the harvested secrets and the network request transmits them to the attacker.
This doesn't work all the time, however. It depends on the model, which isn't always obvious to the user. GitHub Copilot CLI currently uses either Microsoft's own model, mai-code-1.1-flash, which executed the full attack chain on 50 percent of attempts, or one of two OpenAI GPT-5.6 models, both of which refused the attack payload.
Utevsky describes the situation as a model lottery.
"On the paid account we tested, the vulnerable model was not the default and had to be selected by hand," said Utevsky. "But on an account with model selection left on Auto, the router assigned the vulnerable model on some sessions and a safe one on others, with no action by the user away from defaults. The user does not choose, and does not see, which model handled the session."
Adversa says it reported the vulnerability through GitHub's bug bounty program on September 17, 2026, and GitHub's triage team validated the finding but declined to treat it as a vulnerability.
A GitHub spokesperson said as much to , arguing that the user's actions amounted to consent for what followed: "GitHub values the contributions of our security research community and is committed to investigating reported security issues. After investigating, we determined this requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action, and thus is not a product vulnerability. While this is not a security issue with the product itself, we are always looking for opportunities to improve our products."
Adversa disagrees with that call and says the attack chain presently works as described. ®