Rogue Agent Watch › Records › camoleak-github-copilot-chat

CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.

Summary

Legit Security researcher Omer Mayraz disclosed CamoLeak, a critical GitHub Copilot Chat vulnerability (reported CVSS 9.6). It combined remote prompt injection via GitHub's invisible markdown comments with a content-security bypass abusing GitHub's Camo image proxy to silently exfiltrate secrets and source code from private repositories and to steer Copilot's responses. GitHub mitigated it by disabling image rendering in Copilot Chat on 2025-08-14; the research was published in October 2025.

Impact as stated

Proof-of-concept exfiltration of secrets and source code from private repositories and full control of Copilot's responses. Responsibly disclosed via HackerOne and fixed by GitHub before public disclosure; no in-the-wild exploitation reported.

Facts as stated by sources

Actor
Omer Mayraz (Legit Security) (Researcher)
Category
Agent hijack / prompt injection
Models named
GitHub Copilot Chat
Model families
Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Exfiltration
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051.001, AML.T0057

Mitigations as stated

  • GitHub disabled image rendering in Copilot Chat (2025-08-14).

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code
    Legit Security · First-party disclosure · · archived copy
  2. GitHub patches Copilot Chat flaw that could leak secrets
    The Register · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "camoleak-github-copilot-chat". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/camoleak-github-copilot-chat.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction