news.mlab.sh
Back to the feed
vulnerability

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

Medium
Image: The Register
Summary

GitHub Copilot CLI can be tricked into revealing developer secrets by presenting it with a carefully constructed webpage containing encrypted instructions and a private key. GitHub initially dismissed the issue, arguing it requires user action and isn't a product vulnerability, but researchers disagree.

Read the full article at The Register

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.