GitLost: GitHub's AI Agent Tricked Into Leaking Private Repository Data

https://hackread.com/wp-content/uploads/2026/07/gitlost-github-ai-agent-leaking-repository-data-3-1024x576.jpg

Noma Security’s research team, Noma Labs, has disclosed a critical prompt injection vulnerability in GitHub’s new Agentic Workflows. The vulnerability, named GitLost, allowed researchers to trick GitHub’s AI agent into retrieving data from a private repository and posting it publicly by submitting a crafted issue in a public repository belonging to the same organization.

GitHub recently launched Agentic Workflows, a system that pairs GitHub Actions with an AI agent running on Claude or GitHub Copilot. It lets teams define workflows in Markdown, which GitHub converts into GitHub Actions workflows. The agent reads issues, calls tools, and responds on its own as part of normal operation.

The Vulnerability

The vulnerability comes down to prompt injection, where an attacker hides malicious instructions inside content that an AI agentreads. The agent then follows those hidden instructions instead of the ones its operator wrote. With GitLost, the malicious commands were placed in...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE