Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data
ID: 7dc02862-1220-5456-8baf-2dbf65fd49a1
STIX ID: report--7dc02862-1220-5456-8baf-2dbf65fd49a1
Feed Name: GBHackers
Threat Score
A critical prompt-injection flaw (CVE-2025-59145) in GitHub Copilot Chat, dubbed "CamoLeak," let attackers embed invisible markdown prompts in pull requests to coerce the AI into locating secrets in private repositories and exfiltrating them by encoding data into requests to GitHub's trusted Camo image proxy; GitHub patched the issue by disabling image rendering, and the report warns the technique represents a broader AI-mediated exfiltration TTP that could affect other assistants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
