GitHub AI agent leaks private repos when asked nicely
ID: 0cce0b9c-fb00-5321-b1ed-2b0600355aa5
STIX ID: report--0cce0b9c-fb00-5321-b1ed-2b0600355aa5
Feed Name: The Register (Security)
Threat Score
Noma Labs discovered 'GitLost', a critical prompt-injection flaw in GitHub's Agentic Workflows allowing AI agents (e.g., Claude or GitHub Copilot) to be manipulated via a crafted public issue so they fetch and post files from private repositories as public comments; researchers published PoC and workflow reproductions while GitHub had not applied the proposed documentation mitigation, leaving organizations using Agentic Workflows at risk of silent data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
