Security/press release/2026-10-06

GitHub Copilot CLI Vulnerability Allows Secret and Local File Theft via Malicious Web Pages

A vulnerability has been identified in GitHub Copilot CLI that could allow attackers to steal developer secrets and local files. This exploit leverages malicious instructions embedded in specially crafted web pages, which can trick the CLI into exfiltrating sensitive information. The issue highlights a potential risk for developers using the tool.

4 articles from 4 outlets covered this story. Their coverage differs on 2 points. The underlying claim is sourced from a press release.

What do all outlets agree on?

4 outlets covered “GitHub Copilot CLI Vulnerability Allows Secret and Local File Theft via Malicious Web…”. All of them report the following:

  • Vulnerability in GitHub Copilot CLI
  • Allows theft of developer secrets
  • Allows theft of local files
  • Exploitable via malicious web page instructions

Did outlets disagree about this?

Yes. Coverage of “GitHub Copilot CLI Vulnerability Allows Secret and Local File Theft via Malicious Web…” differs on 2 points. Each account below is how a different outlet described the same event:

The attack method is described as 'zombie instructions'

The Register

The attack method is described as 'encrypted prompt injection'

CyberSecurityNews, news.lavx.hu

Which outlets covered this?

All 4 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.

What related stories are there?

Get the week in AI in one email

What happened, which outlets reported it, and where their coverage differed. One issue a week.

The first issue hasn’t gone out yet. Subscribe and it’s the one you’ll get.

We’ll send the digest and nothing else. One-click unsubscribe. Privacy.