GitHub Copilot CLI Vulnerabilities Allow Remote Code Execution and Malware Download
By
sarelta
Kettled twice. Extra chewy, extra trustworthy.
Summary
GitHub Copilot CLI has security vulnerabilities that allow remote code execution via indirect prompt injection, enabling malware to be downloaded and executed without user approval. GitHub acknowledged the issue but considers it a known problem that doesn't present significant security risk, stating they may make the functionality more strict in the future but have nothing to announce currently.
Key quotes
· 4 pulledGitHub responded quickly, 'We have reviewed your report and validated your findings. After internally assessing the finding, we have determined that it is a known issue that does not present a significant security risk.'
Vulnerabilities in the GitHub Copilot CLI expose users to the risk of arbitrary shell command execution via indirect prompt injection without any user approval.
We demonstrate that malware can be downloaded from external servers and executed with no user interaction beyond the initial query to the Copilot CLI.
GitHub Copilot has released a new CLI, which went into general availability two days ago. Upon release, vulnerabilities were identified that bypass the command validation system to achieve remote code execution via indirect prompt.
You might also wanna read

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
GitHub Copilot: A Powerful AI Tool for Debugging Code
The article explores how GitHub Copilot, an AI-powered coding assistant, can significantly streamline the debugging process for developers.

How GitHub's Copilot Secret Scanning Uses AI to Detect Passwords in Code
The article details the development and functionality of GitHub's Copilot secret scanning feature, which uses AI to detect generic passwords
GitHub Copilot CLI Launches 'Rubber Duck' Feature for AI-Powered Code Review
GitHub Copilot has launched a new experimental feature called 'Rubber Duck' in its CLI tool. This feature uses a second AI model from a diff
VS Code Remote-SSH Vulnerability Enables Lateral Movement from Developer Machines to Cloud Servers
A critical vulnerability in Visual Studio Code's Remote-SSH extension creates a post-compromise attack path enabling threat actors to pivot
cybersecuritynews.com·2d ago