← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2025 · 21:20via Embrace The Red (AI agent security)

GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)

Brief

This post is about an important, but also scary, prompt injection discovery that leads to full system compromise of the developer’s machine in GitHub Copilot and VS Code .

It is achieved by placing Copilot into YOLO mode by modifying the project’s settings.json file.

As described a few days ago with Amp , a vulnerability pattern in agents that might be overlooked is that if an agent can write to files and modify its own configuration or update security-relevant settings it can lead to remote code execution. This is not uncommon and is an area to always look for when performing a security review.

Read more on Embrace The Red (AI agent security)