logo

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

ID: 1e323639-87f9-59d9-b0b8-bfdde61a192c

STIX ID: report--1e323639-87f9-59d9-b0b8-bfdde61a192c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-17

Author: Elizabeth Montalbano

...
...

A critical prompt-injection flaw dubbed "GitLost" in GitHub Agentic Workflows allows an unauthenticated attacker to create a public issue that instructs AI-backed workflow agents to read and exfiltrate data from private repositories without compromising accounts or exploiting software bugs. Noma Security released a PoC and disclosed the issue to GitHub; defenders are advised to apply least-privilege repository permissions, isolate untrusted user input from system prompts, and remove cross-repository access for agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.