Full Report
Run the CLI in autopilot mode and take your chances
Analysis Summary
# Vulnerability: Cryptographic Context Injection (CCI) in GitHub Copilot CLI
## CVE Details
- **CVE ID**: Not Assigned (Vendor disputed)
- **CVSS Score**: N/A (Estimated Medium-High based on impact)
- **CWE**: CWE-94: Improper Control of Generation of Code ('Code Injection') / Indirect Prompt Injection
## Affected Systems
- **Products**: GitHub Copilot CLI
- **Versions**: Current versions as of October 2026
- **Configurations**:
- **Autopilot Mode**: The CLI must be running in [autopilot mode](https[:]//docs[.]github[.]com/en/enterprise-cloud@latest/copilot/concepts/agents/copilot-cli/autopilot).
- **Model Selection**: Specifically affects sessions routed to Microsoft’s `mai-code-1.1-flash` model. Sessions using OpenAI `GPT-5.6` models appeared resistant during testing.
## Vulnerability Description
The flaw involves a **Cryptographic Context Injection (CCI)**. Unlike standard prompt injection where malicious instructions are visible to static guardrails, CCI hides instructions within ciphertext.
The attack induces the agent to use its own code execution runtime (e.g., Python) to decrypt the payload. The attack chain uses a "Model Lottery" to bypass security:
1. The agent is directed to a URL containing encrypted instructions and key material.
2. The agent is instructed to "build" a decryption key by reading local sensitive files (like `.env`).
3. After a failed attempt with the "fake" key, the agent is directed to a second valid key to complete decryption.
4. The decrypted instructions then command the agent to send the harvested secrets to an attacker-controlled URL via a network request.
## Exploitation
- **Status**: PoC available (Validated by Adversa AI)
- **Complexity**: Medium (Requires the user to fetch a specific malicious URL)
- **Attack Vector**: Network / Remote (Indirect Prompt Injection)
## Impact
- **Confidentiality**: **High** (Exposure of local environment variables, `.env` files, and developer secrets)
- **Integrity**: **Low** (Potential for unauthorized command execution depending on agent permissions)
- **Availability**: **None**
## Remediation
### Patches
- **None**: GitHub has declined to treat this as a product vulnerability, stating it requires the user to intentionally fetch untrusted content.
### Workarounds
- **Disable Autopilot Mode**: Ensure the CLI requires manual confirmation for every action.
- **Manual Model Selection**: If possible, pin the CLI to known resilient models (e.g., OpenAI GPT-5.6) rather than using "Auto" selection.
- **Restrict URL Fetching**: Avoid using the CLI to fetch or summarize content from untrusted or third-party websites.
## Detection
- **Indicators of Compromise**:
- Audit logs showing Copilot CLI attempting to read sensitive files like `~/.ssh/id_rsa`, `.env`, or `.aws/credentials` followed by an external network request to an unknown domain.
- CLI execution of Python scripts involving `cryptography` or `base64` libraries on externally sourced data.
- **Detection methods**: Monitor EDR (Endpoint Detection and Response) for unusual file access patterns originating from the Copilot CLI process.
## References
- **Adversa AI Blog**: hxxps[:]//adversa[.]ai/blog/cryptographic-context-injection-github-copilot/
- **Original Report**: hxxps[:]//www[.]theregister[.]com/2026/10/06/github_copilot_cli_secrets/
- **GitHub Documentation**: hxxps[:]//docs[.]github[.]com/en/copilot/github-copilot-enterprise/copilot-cli/using-github-copilot-cli