logo

Malicious Commands in GitHub Codespaces Enable RCE

ID: 287d28f4-eabd-5677-bddb-1cc6eb5bd4e3

STIX ID: report--287d28f4-eabd-5677-bddb-1cc6eb5bd4e3

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

...
...

Orca Security researchers found that GitHub Codespaces automatically applies repository-supplied configuration files on startup and when checking out pull requests, allowing attackers to embed commands in .vscode and devcontainer configuration files that execute on environment load. These vectors can lead to remote code execution, theft of GitHub authentication tokens and Codespaces secrets, privilege escalation within GitHub Enterprise environments, and potential abuse of undocumented APIs (including access to Copilot models); Microsoft acknowledges the behavior as by-design but the researchers recommend treating repository configs with zero trust.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.