{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/legit-camoleak-github-copilot-chat-2025/",
 "asOf": "2026-09-26",
 "id": "legit-camoleak-github-copilot-chat-2025",
 "date": "2025-10-08",
 "datePrecision": "day",
 "title": "CamoLeak: hidden PR comments let GitHub Copilot Chat leak private code via image proxy",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Legit Security found that instructions in hidden pull request comments were processed by Copilot Chat for any user viewing the PR, and that GitHub's Camo image proxy could be used to encode private repository content into a sequence of image requests that bypassed the content security policy. Reported via HackerOne, GitHub fixed it on 2025-08-14 by disabling image rendering in Copilot Chat; Legit rates it CVSS 9.6.",
 "whyItMatters": "It showed that a platform's own trusted proxy can become the exfiltration channel for an assistant.",
 "actors": [
  "legit-security",
  "github"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "credentials"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.legitsecurity.com/blog/camoleak-critical-github-copilot-vulnerability-leaks-private-source-code",
   "publisher": "Legit Security",
   "title": "CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code",
   "date": "2025-10-08",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Discovered June 2025; fixed 2025-08-14 by disabling image rendering in Copilot Chat.",
   "locator": "Disclosure timeline"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}