GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
Malicious prompters could easily trick GitHub agents into pulling data from private repositories and then leaking the information as a public comment for anyone to access, according to Noma Labs researchers who named the vulnerability GitLost.
The issue exists in GitHub’s Agentic Workflows, which allow an AI agent powered by Claude or GitHub Copilot to autonomously execute tasks in GitHub Actions.
As the AI security sleuths discovered and detailed in a Monday blog, the workflows are vulnerable to a critical prompt injection flaw that causes GitHub’s AI agent to retrieve data from a private repo by crafting a GitHub issue in a public repository belonging to the same organization.
The attacker simply hides the malicious commands in plain English in the issue body, and the agent will then post this data as a public comment on...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE