Legit Security found that instructions in hidden pull request comments were processed by Copilot Chat for any user viewing the PR, and that GitHub's Camo image proxy could be used to encode private repository content into a sequence of image requests that bypassed the content security policy. Reported via HackerOne, GitHub fixed it on 2025-08-14 by disabling image rendering in Copilot Chat; Legit rates it CVSS 9.6.
Why it matters
It showed that a platform's own trusted proxy can become the exfiltration channel for an assistant.
Key facts
As stated in the sources, with where to find them.
- Discovered June 2025; fixed 2025-08-14 by disabling image rendering in Copilot Chat.Disclosure timeline
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
May 26, 2025
Aug 20, 2025
May 22, 2025
Nov 20, 2025
Oct 31, 2025
Oct 31, 2025