Skip to content
GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection

GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection

Cybersecuritynews Guru Baran February 25, 2026

A critical AI-driven vulnerability in GitHub Codespaces, dubbed RoguePilot, that enabled attackers to silently hijack a repository by embedding malicious instructions inside a GitHub Issue. The flaw, uncovered by researchers at the Orca Research Pod, exploits the seamless integration between GitHub Issues and the in-Codespaces Copilot AI agent, requiring no direct interaction from the attacker […]

Extracted Entities

Companies (1)

Tools (1)

Vulnerabilities (1)