logo

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

ID: 13a37a98-334b-50d9-b956-fb2512811259

STIX ID: report--13a37a98-334b-50d9-b956-fb2512811259

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Noma Security's "GitLost" PoC shows that a crafted public GitHub issue can perform indirect prompt injection against GitHub Agentic Workflows that hold organization-wide read tokens, causing the agent to pull private repository contents and paste them into a public comment; the report explains the attack flow, why it is an architectural limitation, prior similar incidents, and recommends mitigation such as scoping tokens, limiting outputs, and human review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.