STUPID-2026-0048
CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)
Instruction given
Use Copilot Chat to help review a pull request.
Expected behavior
Ignore instructions hidden in untrusted PR content; never exfiltrate private source or secrets.
Actual behavior
The CamoLeak flaw (CVSS 9.6) let attackers plant hidden prompt injections in pull-request descriptions that steered Copilot Chat into silently exfiltrating private source code and secrets — using image rendering as the covert channel.
Damage
Private repositories' source code and secrets could be silently exfiltrated via crafted PR descriptions. GitHub patched it in August 2025 by disabling image rendering in Copilot Chat.
Classification
- Agent
- GitHub Copilot
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.