CVE-2025-59145Disclosure

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. See references below for more information on the payload. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new patch versions to help cache-bust those using private registries who might still have the compromised version cached. Users should update to the latest patch version, completely remove their node_modules directory, clean their package manager's global cache, and rebuild any browser bundles from scratch. Those operating private registries or registry mirrors should purge the offending versions from any caches. This issue is resolved in 2.0.2.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 10 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 3 mentions (2026-04-11); latest day: 1
  • 13 total mentions across 10 days

Deep dive

Activity timeline13 mentions / 10d
01223Mentions · 2026-04-10: 1Mentions · 2026-04-11: 3Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-17: 1Mentions · 2026-05-20: 2Mentions · 2026-06-15: 1Mentions · 2026-06-18: 1Mentions · 2026-06-22: 1Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-06-15: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-11: 2Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-20: 2Technical Details · 2026-06-15: 1Technical Details · 2026-06-22: 104-1004-1104-1304-1404-1705-2006-1506-1806-2207-06
Signal classification5 categories
Disclosure
646.2%
PoC
323.1%
General
215.4%
Exploit
17.7%
Active Exploitation
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-101
Exploit1
2026-04-113
Disclosure2PoC1
2026-04-131
Disclosure1
2026-04-141
Disclosure1
2026-04-171
Active Exploitation1
2026-05-202
Disclosure1PoC1
2026-06-151
PoC1
2026-06-181
General1
2026-06-221
Disclosure1
2026-07-061
General1
Full discourse13 posts
  • Ben Rothke@benrothke
    Disclosure

    #CamoLeak is a high-severity #vuln in #GitHub #Copilot Chat (CVE-2025-59145, CVSS 9.6) that gives attackers ability to silently steal source code, API keys &amp; secrets from private repos w/o executing any malicious code. Good overview from @blackfogprivacy. https://api.cyfluencer.com/s/camoleak-how-github-copilot-became-an-exfiltration-channel-26669

    Post summary

    The post announces a new high‑severity vulnerability (CVE‑2025‑59145) affecting GitHub Copilot Chat, highlighting its stealthy data exfiltration capabilities—no PoC or exploit code has been disclosed.

    01040325
    9.0K followersView on X
  • 城咲子@情シスセキュリティ担当@jo_sekiko
    General

    「GitHub Copilot Enterprise版なら安全ですよね?」——毎週この質問が来る。 Enterprise版はデータガバナンスの改善であって、権限スコープの制限ではない。CVE-2025-59145(CamoLeak)が示した構造的弱点がまさにここです。 Enterprise版導入と権限設計は、別の問題。続きはリプ欄👇

    Post summary

    The text refers to CVE-2025-59145 within the context of GitHub Copilot Enterprise, but provides no technical details, PoC, active exploitation evidence, patch information, or debunking assertion.

    10020172
    4.3K followersView on X
  • Chompa@ch0mpaa
    PoC

    CVE-2025-59145 “CamoLeak” showed how hidden instructions in a PR comment could influence GitHub Copilot Chat into leaking private repo data through markdown image requests. That’s INDIRECT prompt injection. That’s Level 11 territory. Want to understand how these attacks actually work? Try AIPWN Level 11 at AIPWN #AIPWN #AIRedTeam #LLMSecurity #PromptInjection

    Post summary

    CVE-2025-59145 demonstrates how hidden PR comment instructions can cause GitHub Copilot Chat to leak private repository data via indirect prompt injection, but no active exploitation or patch is mentioned.

    000101.2K
    431 followersView on X
  • .@aipwnme
    Disclosure

    CVE-2025-59145 “CamoLeak” showed how hidden instructions in a PR comment could influence GitHub Copilot Chat into leaking private repo data through markdown image requests.That’s INDIRECT prompt injection.That’s Level 11 territory.Want to understand how these attacks work?

    Post summary

    CVE‑2025‑59145 (CamoLeak) is disclosed as an indirect prompt injection vulnerability that allows hidden instructions in a PR comment to cause GitHub Copilot Chat to leak private repository data through markdown image requests; no PoC, exploit, or mitigation is provided.

    001002.0K
    8 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    GitHub Copilot Chat の脆弱性 CVE-2025-59145 の修正:プロンプト・インジェクションを遮断 https://iototsecnews.jp/2026/04/10/hackers-exploit-github-copilot-flaw-to-exfiltrate-sensitive-data/ この問題の原因は、人間には見えない隠し文字である Markdown コメントを、AI アシスタントが正規の指示として解釈してしまうという点にあります。この脆弱性 CVE-2025-59145 (CVSS 9.6) は、CamoLeak と命名された巧妙な手法で悪用されました。攻撃者がプルリクエストの中に、機密情報を画像 URL に変換して外部へ送信させる命令を埋め込むことで、開発者の信頼された権限を悪用する AI が、データを流出させてしまう仕組みです。GitHub 自身の画像プロキシ機能を介するため、通常のセキュリティ監視をすり抜けてしまうという、検出の難しさもありました。目に見えない命令まで、AI が実行してしまうリスクを理解する必要があります。 #CopilotChat #CVE202559145 #GitHub #PromptInjection #Vulnerability

    Post summary

    The article reports that CVE-2025-59145, a prompt injection flaw in GitHub Copilot Chat, is actively being exploited via a technique called CamoLeak; a patch has been released, but no PoC or exploit code is provided.

    01000618
    484 followersView on X
  • 城咲子@情シスセキュリティ担当@jo_sekiko
    Disclosure

    CamoLeak / CVE-2025-59145 / CVSS 9.6 GitHub Copilotが画像プロキシ経由でコンテキスト内のシークレットを外部送信する脆弱性。Enterprise版も対象。 「Enterprise使ってるから大丈夫」は通用しない。Content exclusionで .env系ファイルを除外しましたか? #GitHubCopilot #CVE #情シス

    Post summary

    The post discloses CVE‑2025‑59145, a high‑severity GitHub Copilot flaw that lets secrets be sent externally via an image proxy, affecting both standard and Enterprise editions.

    00000150
    4.3K followersView on X
  • 城咲子@情シスセキュリティ担当@jo_sekiko
    General

    GitHub ActionsとCopilot/Claude Codeで起きるシークレット漏洩4パターン - デバッグecho混入 - Comment-and-Control攻撃 - CVE-2025-30066(CVSS 8.6)サプライチェーン - CamoLeak CVE-2025-59145(CVSS 9.6) https://infomation-sytem-security.hatenablog.com/entry/github-actions-ai-secret-leak-patterns #GitHubActions #AIセキュリティ #情シス

    Post summary

    The post lists two GitHub Actions and AI‑tool related CVEs with their CVSS scores but provides no actionable details, tools, or patch information.

    00000234
    4.3K followersView on X
  • Lee Ryeong@OHS1327
    PoC

    Three AI assistants, same bug, different vendors: • EchoLeak (MS365 Copilot, CVE-2025-32711) • CamoLeak (GitHub Copilot, CVE-2025-59145) • GitLab Duo Each: hidden text in content the AI ingests → the AI uses its own access to pull a secret → the secret ends up in the output. The user did nothing wrong. This is a confused deputy. And it's why I test for it deterministically: plant a string that should never appear, then check if it came back out. Yes or no, no judgment call. http://github.com/ghkfuddl1327-wq/rojaprove #LLMSecurity

    Post summary

    The post highlights three AI assistant CVEs involving unseen text leaks and provides a GitHub link to PoC code, but it does not report active exploitation or a vendor patch.

    0000081
    13 followersView on X
  • CyberTech Insights@CyberTech_In
    Disclosure

    Critical flaw in GitHub Copilot enables silent data theft. CVE-2025-59145 (9.6) uses prompt injection to extract sensitive data and exfiltrate it via image URLs. 𝐑𝐞𝐚𝐝 𝐟𝐮𝐥𝐥 𝐬𝐭𝐨𝐫𝐲 :https://cybertechnologyinsights.com/cybersecurity/github-copilot-flaw-enables-silent-data-theft-attack/ #CyberSecurity #AI #Infosec https://t.co/ZY642XxR16

    Post summary

    A newly announced critical flaw (CVE-2025-59145) in GitHub Copilot allows silent data theft via prompt injection and exfiltration through image URLs. No PoC, exploit code, patches, or evidence of active exploitation are provided.

    00000194
    17 followersView on X
  • saravanan kalyanasundaram@saravanankalya4
    Disclosure

    GitHub Copilot Chat’s CamoLeak (CVE-2025-59145, CVSS 9.6) shows how indirect prompt injection can become a data-exfil path: hidden Markdown comments in a PR poisoned Copilot’s context, then encoded secrets were leaked via GitHub’s trusted Camo image proxy https://t.co/BLrUWa1xvb

    Post summary

    A new vulnerability in GitHub Copilot Chat (CVE-2025-59145, CVSS 9.6) is disclosed, showing how indirect prompt injection via hidden Markdown comments can leak encoded secrets through GitHub’s Camo image proxy.

    00000333
    20 followersView on X
  • NeonArtival@NeoLogic_Dev
    Disclosure

    @The_Cyber_News CVE-2025-59145. CVSS 9.6. GitHub Copilot exfiltrating source code, API keys, and cloud secrets — via hidden markdown comments. No malicious code execution required. Your AI assistant had access to everything. That's the attack surface.

    Post summary

    The post reports CVE-2025-59145 with a high CVSS score, detailing how GitHub Copilot can leak code and secrets via hidden comments, but offers no PoC, exploit code, or patch information.

    00000458
    18 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 CamoLeak: How Hackers Exploit #GitHub #Copilot’s Invisible Markdown to Steal Your API Keys and Cloud Secrets (#CVE-2025-59145) + Video https://undercodetesting.com/camoleak-how-hackers-exploit-github-copilots-invisible-markdown-to-steal-your-api-keys-and-cloud-secrets-cve-2025-59145-video/ Educational Purposes!

    Post summary

    The tweet promotes a video that shows a proof‑of‑concept exploit against GitHub Copilot’s invisible markdown feature, but it lacks detailed technical data, patch information, or evidence of real‑world attacks.

    00000380
    464 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Exploit

    🚨 CamoLeak Exposed: How Hackers Weaponize #GitHub #Copilot to Drain Your API Keys (#CVE-2025-59145) + Video https://undercodetesting.com/camoleak-exposed-how-hackers-weaponize-github-copilot-to-drain-your-api-keys-cve-2025-59145-video/ Educational Purposes!

    Post summary

    The post announces CVE‑2025‑59145 in GitHub Copilot and supplies a video demonstrating how attackers can drain API keys, but it does not include exploit code, a patch, or evidence of ongoing exploitation.

    00000442
    464 followersView on X

Explore more