Rogue Agent Watch › Records › camoleak-github-copilot-chat
CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.
Summary
Legit Security researcher Omer Mayraz disclosed CamoLeak, a critical GitHub Copilot Chat vulnerability (reported CVSS 9.6). It combined remote prompt injection via GitHub's invisible markdown comments with a content-security bypass abusing GitHub's Camo image proxy to silently exfiltrate secrets and source code from private repositories and to steer Copilot's responses. GitHub mitigated it by disabling image rendering in Copilot Chat on 2025-08-14; the research was published in October 2025.
Impact as stated
Proof-of-concept exfiltration of secrets and source code from private repositories and full control of Copilot's responses. Responsibly disclosed via HackerOne and fixed by GitHub before public disclosure; no in-the-wild exploitation reported.
Facts as stated by sources
- Actor
- Omer Mayraz (Legit Security) (Researcher)
- Category
- Agent hijack / prompt injection
- Models named
- GitHub Copilot Chat
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Exfiltration
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051.001, AML.T0057
Mitigations as stated
- GitHub disabled image rendering in Copilot Chat (2025-08-14).
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
Sources (2)
- CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code
Legit Security · First-party disclosure · · archived copy - GitHub patches Copilot Chat flaw that could leak secrets
The Register · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "camoleak-github-copilot-chat". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/camoleak-github-copilot-chat.json — CC BY-SA 4.0.