# GitHub Copilot CLI Exposes Developer Secrets to Malicious Web Pages

> Source: <https://osintsights.com/github-copilot-cli-exposes-developer-secrets-to-malicious-web-pages>
> Published: 2026-10-06 13:40:14+00:00

GitHub Copilot CLI has a vulnerability that can expose developer secrets to malicious web pages through a clever attack method called Cryptographic Context Injection (CCI), which tricks the tool into decrypting and executing hidden instructions. This exploit allows hackers to tap into sensitive information, putting developers at risk.
