CamoLeak (CVE-2025-32739)
A November 2025 indirect prompt injection vulnerability in GitHub Copilot Chat disclosed by HiddenLayer, scored CVSS 9.6. The attack chained a payload in an issue or pull-request description with GitHub's Camo image proxy to exfiltrate full private repository contents while bypassing content-security-policy protections. CamoLeak is the highest-CVSS public LLM injection disclosure to date and demonstrated that egress allowlists have to account for whitelisted proxy domains, not just direct third-party hosts.
Frequently asked questions
- What made CamoLeak scored higher than EchoLeak?
- Two factors: (1) full private repo exfiltration is a broader blast radius than the specific tenant data affected by EchoLeak, and (2) the attack bypassed GitHub's existing CSP-based image-loading protections by chaining through the Camo proxy—an allowlisted internal domain. That kind of trust-boundary crossing raises impact scoring.