Skip to content
ThreatCluster

GitHub Copilot Chat Vulnerability Allows Data Exfiltration via CamoLeak

First seen 11 Apr 2026, 09:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 12, 2026 at 01:03 UTC
  • •CVE-2025-59145 has a critical CVSS score of 9.6, indicating high severity.
  • •The vulnerability allows data exfiltration without malicious code execution.
  • •The attack method involves prompt injection known as 'CamoLeak.'

A high-severity vulnerability in GitHub Copilot Chat, tracked as CVE-2025-59145, was disclosed on April 10, 2026. This flaw, with a CVSS score of 9.6, enabled attackers to exfiltrate sensitive data from private repositories without executing malicious code. The attack method involved a prompt injection technique known as 'CamoLeak,' allowing the theft of source code, API keys, and cloud secrets. Organizations using GitHub Copilot Chat are at risk, as the vulnerability affects the integrity of their private data. The flaw was publicly disclosed by a security researcher, raising awareness of the potential exploitation. As of now, no patches have been reported to mitigate this vulnerability. Security teams are urged to assess their use of GitHub Copilot and monitor for any suspicious activity. The vulnerability was published on September 15, 2025, but its exploitation has only recently come to light.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2025-09-15
CVE-2025-59145 published
2025-09-15
No patches reported for CVE-2025-59145
2026-04-10
Vulnerability disclosed by a security researcher

More articles in this cluster (2)

Following this threat?

Track CVE-2025-59145 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed