Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
ID: 13a37a98-334b-50d9-b956-fb2512811259
STIX ID: report--13a37a98-334b-50d9-b956-fb2512811259
Feed Name: The Hacker News
Threat Score
Noma Security's "GitLost" PoC shows that a crafted public GitHub issue can perform indirect prompt injection against GitHub Agentic Workflows that hold organization-wide read tokens, causing the agent to pull private repository contents and paste them into a public comment; the report explains the attack flow, why it is an architectural limitation, prior similar incidents, and recommends mitigation such as scoping tokens, limiting outputs, and human review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
