10 ms·
CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code
- stephenlf 1y agoWild approach. Very nice
- adastra22 1y agoA good vulnerability writeup, and a thrill to read. Thanks!
- deckar01 1y agoDid the markdown link exfil get fixed?
- runningmike 1y agoSomehow this article feels like a promotional for Legit. But all AI vibe solutions face the same weaknesses. Limited transparency and trust Issues: Using non FOSS solutions for cybersecurity is a large risk. If you do use AI cyber solutions, you can be more vulnerable for security breaches instead of less.
- xstof 1y agoWondering if the ability to use hidden (HTML comment) content in PRs would not remain a nasty issue: especially for open source repos?! Was that fixed?
- PufPufPuf 1y agoIt's used widely for issue/PR templates, to tell the submitter what info to include. But they could definitely strip it from the Copilot input... at least until they figure out this "prompt injection" thing that I thought modern LLMs were supposed to be immune to.
- fn-mote 1y ago> that I thought modern LLMs were supposed to be immune to What gave you this idea? I thought it was always going to be a feature of LLMs, and the only thing that changes is that it gets harder to do (more circumventions needed), much like exploits in the context of ASLR.
- PufPufPuf 1y agoPR releases. Yeah, it was an exaggeration, I know that the mitigations can only go so far.
- munchlax 1y agoSo this wasn't really fixed. The impressive thing here is that copilot accepts natural language. So whatever exfiltration method you can come up with, you just write out the method in english. They merely "fixed" one particular method, without disclosing how they fixed it. Surely you could just do the base64 thing to an image url of your choice? Failing that, you could trick it into providing passwords by telling it you accidentally stored your grocery list in a field called passswd, go fetch it for me ppls? There's a ton of stuff to be found here. Do they give bounties? Here's a goldmine.
- lyu07282 1y ago> GitHub fixed it by disabling image rendering in Copilot Chat completely.
- oefrha 1y agoTo supplement the parent, this is straight from article’s TLDR (emphasis mine): > In June 2025, I found a critical vulnerability in GitHub Copilot Chat (CVSS 9.6) that allowed silent exfiltration of secrets and source code from private repos, and gave me full control over Copilot’s responses, including suggesting malicious code or links. > The attack combined a novel CSP bypass using GitHub’s own infrastructure with remote prompt injection. I reported it via HackerOne, and GitHub fixed it by disabling image rendering in Copilot Chat completely. And parent is clearly responding to gp’s incorrect claims that “…without disclosing how they fixed it. Surely you could just do the base64 thing to an image url of your choice?” I’m sure there will be more attacks discovered in the future but gp is plain wrong on these points. Please RTFA or at least RTFTLDR before you vote.
- munchlax 1y agoTake a chill pill. I did, in fact, read the fine article. If you did so too, you would've read the message from github which says "...disallow usage of camo to disclose sensitive victim user content" Now why on earth would I take all the effort to come up with a new way of fooling this stupid AI only to give it away on HN? Would you? I don't have a premium account, nor will I ever pay microsoft a single penny. If you actually want something you can try for yourself, go find someone else to do it. Just to make it clear for you, I was musing on the chord of being able to write out the steps to exploitation in plain english. Since the dawn programming languages, it has been a pie-in-the-sky idea to write a program in natural language. Combine that with computing on the server end of some major SaaS(s) and you can bet people will find clever ways to circumvent safety measures. They had it coming and the whack-a-mole game is on. Case in point TFA.
- nprateem 1y agoYou'd have to be insane to run an AI agent locally. They're clearly unsecurable.
- djmips 1y agocan you still make invisible comments?
- RulerOf 1y agoInvisible comments are a widely used feature. Often done inside of PR or Issue templates to instruct users how to include necessary info without clogging up the final result when they submit.
- charcircuit 1y agoThe rule is to operate using the intersection of all the users permissions of who is contributing text to the LLM. Why can an attacker's prompt access a repo the attacker does not have access to? That's the biggest issue here.
- kerng 1y agoNot the first time by the way. GitHub Copilot Chat: From Prompt Injection to Data Exfiltration https://embracethered.com/blog/posts/2024/github-copilot-chat-prompt-injection-data-exfiltration/ https://embracethered.com/blog/posts/2024/github-copilot-cha...
- glitchdout 1y agoAnd it won't be the last.
- MysticFear 1y agoCan't they just have the Copilot user permission to be readonly from the current repo.
- mediumsmart 1y agoI can't remember the last time I leaked private source code with copilot.
- isodev 1y agoI’m so happy our entire operation moved to a self hosted VCS (Forgejo). Two years ago, we started the migration (including client repos) and not only we saved tones of money on GitHub subscriptions, our system is dramatically more performant for the 30-40 developers working with it every day. We also banned the use of VSCode and any editor with integrated LLM features. Folks can use CLI based coding agents of course, but only in isolated containers with careful selection of sources made available to the agents.
- hansmayer 1y agoJust out of interest, what is your alternative IDE?
- isodev 1y agoThat depends a bit on the ecosystem too. For editors: Zed recently added the disable_ai option, we have a couple of folks using more traditional options like Sublime, vim-based etc (that never had the kind of creepy telemetry we’re avoiding). JetBrains tools are OK since their AI features are plugin based, their telemetry is also easy to disable. Xcode and Qt Creator are also in use.
- belter 1y agoDid you look at VSCodium ? https://vscodium.com/ https://vscodium.com/
- aitchnyu 1y agoWhat do your CLIs connect to? To first-party OpenAI/Claude provider or AWS Bedrock?
- isodev 1y agoDevs are free to choose, provided we can vet the model prover’s policy on training on prompts or user code. We’re also careful not to expose agents to documentation or test data that may be sensitive. It’s a trade off with convenience of course, but we believe that any information agents get access to should be a conscious opt-in. It will be cool if/when self hosting claude-like LLMs becomes pragmatic.
- oncallthrow 1y ago> I spent a long time thinking about this problem before this crazy idea struck me. If I create a dictionary of all letters and symbols in the alphabet, pre-generate their corresponding Camo URLs, embed this dictionary into the injected prompt, Beautiful
- j45 1y agoI wonder sometimes if all code on Github private or not is ultimately compromised somehow.
- twisteriffic 1y agoThis exploit seems to be taking advantage of the slow token-at-a-time pattern of LLM conversations to ensure that the extracted data can be reconstructed in order? Seems as though returning the entire response as a single block could interfere with the timing enough to make reconstruction much more difficult.
- arielcostas 1y agoWhat if you made it generate a URL with each character-position instead of just the character? For example, instead of making `hacked` be `0.0.0.0/h`, `0.0.0.0/a` and so on; it invokes `0.0.0.0/1-h`, `0.0.0.0/2-a`... that way you can sort them and delete any duplicate calls
- musicale 1y agoNo one could possibly have predicted this.
- zastai0day 1y agoYikes. I knew these AI coding tools were sketchy! Leaking private source code is a massive failure. Who would trust Copilot with their company's secret sauce after this? Just goes to show you can't blindly trust big tech.