Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
GitHub validated the exploit and ruled it "not a product vulnerability," since the user had asked Copilot to fetch the page, which is, to be fair, the product.