GitHub Copilot CLI, a tool that brings agentic coding assistance to the command line, is susceptible to a prompt injection technique that uses encrypted payloads to bypass static content filters. Adversa AI describes CCI as a variant of a vulnerability previously found in Grok. The attack chain begins when a user asks Copilot CLI to fetch a web page in autopilot mode. The page contains encrypted content, decryption instructions, and two decryption keys. The first key is a template that the agent attempts to build by reading targeted files from disk, such as a .env file containing secrets. That decryption fails. The second key succeeds, and the agent is instructed to fetch another URL that includes the harvested secrets, transmitting them to the attacker.
Crucially, the vulnerability does not work with every model. GitHub Copilot CLI uses either Microsoft's own model, mai-code-1.1-flash, which executed the full attack chain in 50 percent of attempts, or one of two OpenAI GPT-5.6 models, both of which refused the payload. Adversa's Rony Utevsky described this as a 'model lottery': users who leave model selection on Auto may be assigned a vulnerable or safe model without their knowledge or consent.
Adversa reported the finding through GitHub's bug bounty program on September 17, 2026. GitHub's triage team validated the report but determined it was not a product vulnerability. A GitHub spokesperson argued that the attack requires the user to intentionally direct Copilot CLI to fetch attacker-controlled content and confirm the action. Adversa disagrees with this assessment, noting that in autopilot mode the chain can proceed without explicit confirmation from the user.