GitHub Copilot CLI Exposes Developer Secrets to Malicious Web Pages GitHub Copilot CLI contains a vulnerability that lets malicious web pages expose developer secrets via an attack method called Cryptographic Context Injection (CCI), which tricks the tool into decrypting and executing hidden instructions. The exploit allows attackers to access sensitive information, putting developers who use the CLI at risk. GitHub Copilot CLI has a vulnerability that can expose developer secrets to malicious web pages through a clever attack method called Cryptographic Context Injection CCI , which tricks the tool into decrypting and executing hidden instructions. This exploit allows hackers to tap into sensitive information, putting developers at risk.