research
Published 2026-10-06
Verified 2026-10-07

Adversa AI: "Cryptographic Context Injection" makes GitHub Copilot CLI in autopilot read a developer's .env.prod and send it to an attacker from one web page in 28 seconds; GitHub declined to treat it as a vulnerability

Adversa AI published research on 6 October 2026 showing its Cryptographic Context Injection (CCI) technique, first shown in August against chat assistants, working against GitHub Copilot CLI. A developer runs the agent in autopilot mode and asks it to read an external web page. The page carries its instructions as ciphertext and asks the agent to decrypt it with Python, offering two keys: one is a template that can only be filled in by reading local files, so the agent reads the targeted files while preparing it, and the second, real key reveals a follow-up instruction to fetch another URL with the harvested contents as a parameter. In Adversa's demonstration the full contents of a .env.prod file reached the attacker's endpoint in 28 seconds, with no confirmation prompt and nothing in the transcript showing the destination host or that file contents had left the machine. Because the instructions only exist as readable text after the agent decrypts them in its own runtime, static prompt-injection filters do not see them. Adversa says the chain needs autopilot mode and a permissive model; on its paid test account the vulnerable model had to be picked by hand, but with model selection on Auto the router sometimes assigned it without the user knowing. Adversa says the chain still reproduced as of 1 October; GitHub's bug bounty team validated the finding but declined to treat it as a vulnerability, and concrete payloads were withheld. Primary: Adversa AI; wire: Cyber Security News.

Product
GitHub Copilot CLI (autopilot mode; model-dependent)
Versions
n/a — no CVE; GitHub has not classed it as a vulnerability
Exploited in Australia?
unknown
Patch to
Do not run coding agents in autopilot against untrusted URLs. Pin a model rather than relying on Auto selection, turn on the opt-in controls that confirm shell commands, file reads and outbound requests, and run agents in a sandbox or container without production secrets on disk. Keep .env and credential files out of agent working directories, restrict egress to known hosts, and log agent sessions so the sequence untrusted content, code run, local file read, new outbound host can be detected.

Primary: Adversa AI — Cryptographic Context Injection against GitHub Copilot CLI (6 Oct 2026) · Cyber Security News — GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection (6 Oct 2026)

ai identity