Last seen December 11, 2025

GitHub Copilot Prompt Injection Vulnerability

Evidence indicates that GitHub Copilot is affected by prompt injection.

Technical Severity
Low severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that GitHub Copilot is affected by prompt injection.

Why This Matters

The evidence matters to defenders using GitHub Copilot because it may let untrusted content influence connected tools or sensitive workflows.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether GitHub Copilot is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Dec 06, 2025 05:30

Last Seen

Dec 11, 2025 05:30

Exploitation status: UNKNOWN

Primary entities:

GitHub Microsoft GitHub Copilot Microsoft Copilot AI Agents Prompt Injection

Timeline

  • Incident first seen
    Dec 06, 2025 05:30

    BugSkan first recorded this incident.

  • Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks - The Hacker News
    Dec 06, 2025 05:30

    thehackernews.com ยท Vulnerability

  • Copilot's No Code AI Agents Liable to Leak Company Data - Dark Reading | Security
    Dec 11, 2025 05:30

    darkreading.com ยท Vulnerability

  • Latest observed development
    Dec 11, 2025 05:30

    Most recent source or update associated with this incident.

  • Material change
    Aug 18, 2026 14:07

    ACT -> REVIEW

  • Material change
    Aug 18, 2026 14:07

    recommended action updated

  • Material change
    Aug 18, 2026 14:07

    why it matters updated

Sources

Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks - The Hacker News

thehackernews.com ยท Dec 06, 2025 05:30

Security researcher Ari Marzouk disclosed "IDEsaster," a collection of over 30 vulnerabilities, with 24 assigned CVEs, affecting various AI-powered Integrated Development Environments (IDEs) like GitHub Copilot and Cursor. These flaws enable attackers to chain prompt injection techniques with legitimate IDE features and auto-approved AI agent tool calls to achieve sensitive data exfiltration and remote code execution (RCE).

Open publisher source
Copilot's No Code AI Agents Liable to Leak Company Data - Dark Reading | Security

darkreading.com ยท Dec 11, 2025 05:30

Microsoft Copilot Studio's AI agents are susceptible to prompt injection, a vulnerability that allows users to bypass configured security mandates. This inherent issue leads to unauthorized data disclosure, such as accessing sensitive customer details, and workflow hijacking, enabling attackers to manipulate data and processes.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence