A vulnerability in GitHub Codespaces allows for passive prompt injection via GitHub issues that can lead to full repository takeover by exfiltrating the GITHUB_TOKEN secret through manipulated instructions automatically processed by GitHub Copilot.