Home / Companies / MintMCP / Blog / Post Details
Content Deep Dive

CamoLeak: a copilot chat vulnerability that exfiltrated private repo secrets via GitHub's own image proxy

Blog post from MintMCP

Post Details
Company
Date Published
Author
MintMCP
Word Count
817
Company Posts That Month
93
Language
English
Hacker News Points
-
Post removed?
No
Summary

CamoLeak, disclosed in October 2025 as CVE-2025-59145 with a CVSS score of 9.6, was a critical GitHub Copilot Chat vulnerability chain that could silently leak private repository code, AWS keys, security tokens, and other sensitive information. The attack used hidden Markdown comments in pull requests to inject instructions that Copilot could parse despite their being invisible in GitHub’s standard interface, then exploited Copilot’s access to the logged-in user’s private repository context to retrieve sensitive data. Attackers encoded stolen information character by character through requests routed via GitHub’s Camo image proxy, allowing them to reconstruct data from requests to an attacker-controlled server without executing code on the victim’s device. Researcher Omer Mayraz of Legit Security reported the flaw through HackerOne in June 2025, and GitHub mitigated it on August 14 by disabling image rendering in Copilot Chat and blocking Camo’s use for chat-rendered content; the issue was publicly disclosed nearly two months later.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 25 1,759 518 180 +12%
Secrets Management 5 1,971 393 127 +1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.