A recently discovered vulnerability in GitHub’s Copilot CLI could let malicious web pages manipulate the coding agent to access local developer files and send this data to an external server.
Understanding Cryptographic Context Injection
This security flaw, known as Cryptographic Context Injection (CCI), involves embedding harmful instructions within encrypted text. This method complicates detection by conventional prompt-injection filters.
Adversa AI identified the issue, which arises when Copilot CLI operates in autopilot mode and the developer requests a review of an external URL. The vulnerability was demonstrated when the tool accessed a local file and transmitted its contents to a remote endpoint in under 30 seconds, without alerting the user.
Mechanics of the Vulnerability
The breach leverages prior CCI research on Grok, where encrypted instructions were decrypted in an AI environment and mistakenly trusted. The Copilot CLI receives these commands encrypted, with Python used to decrypt them.
While static filters can inspect visible text, they typically do not execute cryptographic operations to uncover hidden messages. Once Copilot CLI decrypts the data, it may treat it as legitimate internal instructions rather than a threat from an untrusted source.
Implications for Developers
The attack chain involves a deceptive key preparation phase, where one key is real and another is a template prompting file reads. The first decryption fails intentionally, but sensitive data is already captured, followed by successful decryption of further instructions.
Researchers warn that this technique can target various data accessible to the agent, such as source code and configuration files. The inconsistency in safety behavior between different Copilot models, as noted by Adversa AI, poses additional concerns for developers.
GitHub’s bug bounty team acknowledged the report yet did not classify it as a security flaw, citing user consent to Copilot’s actions. However, researchers argue that encryption circumvents safeguards rejecting plaintext instructions.
Preventive Measures and Outlook
Organizations should restrict AI agents from browsing untrusted web pages with extensive file and network permissions. Security teams must log tool operations, alert on unusual content execution, and avoid storing sensitive data in agent-accessible locations.
This incident underscores the need for vigilance in managing AI coding tools, emphasizing the importance of monitoring actual agent activities in addition to input analysis.
