Critical
CVE-2025-53773
GitHub Copilot Exploitation via CVE-2025-53773 Causes Developer Machine Compromise
Vendor / product: GitHub Copilot, Visual Studio
Event date: 2025-08-12
Victim organization: unknown
Public PoC: Yes
First tracked by RiskWire: 2026-09-05
Sources & citations (3)
- The Orchestrator's Deputy Has No Scope: Ambient Authority Is the Root Bug in Multi-Agent AI dev.to · 2026-09-06
- JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors dev.to · 2026-09-06
- Indirect Prompt Injection via API Responses: The Attack Agents Cannot Stop at the LLM Layer dev.to · 2026-09-06
References
See CVE-2025-53773 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →