Johann Rehberger showed that injected instructions in project content could make GitHub Copilot in VS Code edit workspace settings to switch off command confirmations, after which it could run arbitrary terminal commands. He reported it on 2025-06-29 and Microsoft patched it in the August 2025 Patch Tuesday.
Why it matters
Agents that can write their own permission settings can escalate from text injection to host compromise.
Key facts
As stated in the sources, with where to find them.
- Reported 2025-06-29; fixed in the August 2025 Patch Tuesday.Disclosure section
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Jul 28, 2025
Aug 1, 2025
Aug 4, 2026
May 7, 2026
Jan 8, 2026
Nov 20, 2025