GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)(embracethered.com)
embracethered.com
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)
https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
1 comments
tl;dr: Vuln only possible by placing Copilot into YOLO mode. And it's fixed with the August Patch Tuesday release.