logo

GitHub AI agent leaks private repos when asked nicely

ID: 0cce0b9c-fb00-5321-b1ed-2b0600355aa5

STIX ID: report--0cce0b9c-fb00-5321-b1ed-2b0600355aa5

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-23

...
...

Noma Labs discovered 'GitLost', a critical prompt-injection flaw in GitHub's Agentic Workflows allowing AI agents (e.g., Claude or GitHub Copilot) to be manipulated via a crafted public issue so they fetch and post files from private repositories as public comments; researchers published PoC and workflow reproductions while GitHub had not applied the proposed documentation mitigation, leaving organizations using Agentic Workflows at risk of silent data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.