logo

GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos

ID: 82d1dc4f-117c-56dc-8095-0b0ba621553e

STIX ID: report--82d1dc4f-117c-56dc-8095-0b0ba621553e

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Divya

...
...

Noma Labs discovered “GitLost,” a critical prompt‑injection vulnerability in GitHub Agentic Workflows that can be triggered by creating and assigning a malicious issue; AI agents reading the issue can be manipulated to execute hidden instructions, access private repositories, and post extracted data publicly. The report includes a proof‑of‑concept exfiltrating private README content, describes a guardrail bypass technique, and recommends strict trust boundaries, least privilege for agents, output restrictions, and input sanitization; GitHub was responsibly notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.