RoguePilot: Exploiting GitHub Copilot for a Repository Takeover

We forced GitHub to prompt-inject itself. It allowed us to control Copilot’s responses and exfiltrate Codespaces’ GITHUB_TOKEN secret. The end result was a repository takeover. This vulnerability is a type of Passive Prompt Injection, where malicious instructions are embedded in data, content, or environments that the model later processes automatically, without any direct interaction from […]

The post RoguePilot: Exploiting GitHub Copilot for a Repository Takeover appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/roguepilot-github-copilot-vulnerability/
侵权请联系站方: [email protected]

相关推荐

换一批