Hidden web instructions can prompt Copilot CLI to expose developer secrets
Researchers say GitHub Copilot CLI can be tricked into exposing developer secrets through malicious instructions hidden in encrypted web content. The technique, called Cryptographic Context Injection, matters because it may evade safeguards that scan text for harmful instructions, although its success depends on which AI model handles the session.
In the researchers’ tests, the attack succeeded in 50 per cent of attempts using Microsoft’s mai-code-1.1-flash model, while two OpenAI GPT-5.6 models refused it. With autopilot enabled, the CLI could read secrets such as those in a `.env` file, then send them to an attacker while following instructions from the page. Adversa reported the issue to GitHub on 17 September 2026; GitHub validated the finding but said the user had directed the tool to fetch untrusted content and confirmed the action, so it did not consider this a product vulnerability.
- Encrypted web instructions may lead Copilot CLI to expose developer secrets.
- The tested attack worked in half of attempts with one Microsoft model.
- GitHub says fetching untrusted content requires user direction and confirmation.
New here? Start with this
GitHub Copilot CLI is an artificial intelligence tool developed by Microsoft-owned GitHub that assists software developers by suggesting code and automating routine tasks. Developers rely on it because it speeds up their work and reduces the time spent on repetitive coding.
Researchers have discovered that Copilot CLI can be tricked into revealing sensitive information that developers keep secret, such as passwords and security credentials stored in project files. The attack works by hiding malicious instructions within encrypted web content in a way designed to bypass built-in safety systems.
Passwords and credentials are extremely valuable to attackers because they grant direct access to company systems and data. This discovery highlights a potential weakness in how AI-powered tools validate requests, even when equipped with safety measures.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Security researchers argue this represents a genuine vulnerability because hidden instructions in encrypted content make attacks particularly difficult for users to anticipate or defend against. They contend that products should maintain layered safeguards to prevent secrets from being exposed even when users initiate content fetching, viewing the 50 per cent success rate as evidence of exploitable behaviour that goes beyond user responsibility. From this perspective, developers shouldn't have their secrets compromised simply for using a tool in ways that seem reasonably safe.
The case against
GitHub contends that users must bear responsibility for directing their tools to untrusted sources and explicitly confirming such actions. Since the user made deliberate choices at each step, GitHub argues this represents user agency rather than a product flaw—treating all scenarios where a user's confirmed action has consequences as vulnerabilities would conflate product design with user accountability and impose unrealistic standards on tools that rightfully respect user directives.
Entertainment Geopolitics Horror Politics
Read the full article at the source →
Originally published by The Register as “Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets”.