agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard critical confidence: confirmed status: final

GitHub Copilot could be prompt-injected into disabling its own approvals, enabling RCE (CVE-2025-53773)

2025-github-copilot-autoapprove-rce · 2025-08-12

A prompt injection planted in source code, web pages, GitHub issues, or tool responses could instruct GitHub Copilot in VS Code to edit its own .vscode/settings.json and set chat.tools.autoApprove (the experimental auto-approve / "YOLO mode"), disabling all user confirmations so it would run shell commands without approval — remote code execution (CVE-2025-53773).

System

Framework
GitHub Copilot (VS Code)
Tools
vscode, shell, github-copilot
Vendor
Microsoft / GitHub
Autonomy
human-in-the-loop

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → excessive-agency/missing-approval-gate → unsafe-action/unauthorized-write
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

A prompt injection embedded in untrusted content the agent processed (source code, a web page, a GitHub issue, or a tool response) instructed Copilot to add "chat.tools.autoApprove": true to .vscode/settings.json. That experimental setting disables all confirmation prompts, after which the agent could run shell commands and other actions without approval, yielding code execution.

Root cause

The agent was able to modify its own configuration — the very setting that governs whether its actions require human approval — from untrusted input. Self-modification of the approval boundary let a single injection escalate to unattended command execution.

Contributing factors

  • An experimental auto-approve setting could remove all human confirmation for agent actions.
  • The agent could write to its own settings file from untrusted, injected content.
  • Untrusted content was treated with the same authority as user instructions.

Detection

Discovered by researcher Johann Rehberger (wunderwuzzi) and independently by Markus Vervier and Ari Marzuk; reported to Microsoft on 2025-06-29.

Recovery

Microsoft confirmed it was tracking the issue and shipped a fix in the August 2025 Patch Tuesday release.

Prevention

Never allow an agent to change its own approval/permission settings from untrusted input; gate security-relevant configuration behind explicit, out-of-band user action; treat retrieved content as untrusted; keep destructive/auto-approve modes off by default and clearly flagged.

Blast radius

Data
Exploitation allowed arbitrary shell-command execution on the developer's machine via the agent, once confirmations were disabled. internal
User harm
A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
Scope
GitHub Copilot + VS Code users before the August 2025 fix
Reversibility
reversible

References

CWE
CWE-94
OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051
Tags
prompt-injection rce copilot auto-approve self-modification cve

Sources

Cite this incident

@misc{2025-github-copilot-autoapprove-rce,
  title = {GitHub Copilot could be prompt-injected into disabling its own approvals, enabling RCE (CVE-2025-53773)},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-github-copilot-autoapprove-rce/}
}