GitHub Copilot could be prompt-injected into disabling its own approvals, enabling RCE (CVE-2025-53773)
2025-github-copilot-autoapprove-rce · 2025-08-12
A prompt injection planted in source code, web pages, GitHub issues, or tool responses could instruct GitHub Copilot in VS Code to edit its own .vscode/settings.json and set chat.tools.autoApprove (the experimental auto-approve / "YOLO mode"), disabling all user confirmations so it would run shell commands without approval — remote code execution (CVE-2025-53773).
System
- Framework
- GitHub Copilot (VS Code)
- Tools
- vscode, shell, github-copilot
- Vendor
- Microsoft / GitHub
- Autonomy
- human-in-the-loop
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → excessive-agency/missing-approval-gate → unsafe-action/unauthorized-write
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
A prompt injection embedded in untrusted content the agent processed (source code, a web page, a GitHub issue, or a tool response) instructed Copilot to add "chat.tools.autoApprove": true to .vscode/settings.json. That experimental setting disables all confirmation prompts, after which the agent could run shell commands and other actions without approval, yielding code execution.
Root cause
The agent was able to modify its own configuration — the very setting that governs whether its actions require human approval — from untrusted input. Self-modification of the approval boundary let a single injection escalate to unattended command execution.
Contributing factors
- An experimental auto-approve setting could remove all human confirmation for agent actions.
- The agent could write to its own settings file from untrusted, injected content.
- Untrusted content was treated with the same authority as user instructions.
Detection
Discovered by researcher Johann Rehberger (wunderwuzzi) and independently by Markus Vervier and Ari Marzuk; reported to Microsoft on 2025-06-29.
Recovery
Microsoft confirmed it was tracking the issue and shipped a fix in the August 2025 Patch Tuesday release.
Prevention
Never allow an agent to change its own approval/permission settings from untrusted input; gate security-relevant configuration behind explicit, out-of-band user action; treat retrieved content as untrusted; keep destructive/auto-approve modes off by default and clearly flagged.
Blast radius
- Data
- Exploitation allowed arbitrary shell-command execution on the developer's machine via the agent, once confirmations were disabled. internal
- User harm
- A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
- Scope
- GitHub Copilot + VS Code users before the August 2025 fix
- Reversibility
- reversible
References
- CWE
- CWE-94
- OWASP LLM
- LLM01 LLM06
- MITRE ATLAS
- AML.T0051
- Tags
- prompt-injection rce copilot auto-approve self-modification cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-github-copilot-autoapprove-rce/
@misc{2025-github-copilot-autoapprove-rce,
title = {GitHub Copilot could be prompt-injected into disabling its own approvals, enabling RCE (CVE-2025-53773)},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-github-copilot-autoapprove-rce/}
}