Chronicle/Attacks & incidents

CamoLeak: hidden PR comments let GitHub Copilot Chat leak private code via image proxy

AttackVulnerability disclosureSignificance assistant-drafted

Legit Security found that instructions in hidden pull request comments were processed by Copilot Chat for any user viewing the PR, and that GitHub's Camo image proxy could be used to encode private repository content into a sequence of image requests that bypassed the content security policy. Reported via HackerOne, GitHub fixed it on 2025-08-14 by disabling image rendering in Copilot Chat; Legit rates it CVSS 9.6.

Why it matters

It showed that a platform's own trusted proxy can become the exfiltration channel for an assistant.

Key facts

As stated in the sources, with where to find them.

  • Discovered June 2025; fixed 2025-08-14 by disabling image rendering in Copilot Chat.Disclosure timeline

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records