‘GitLost’: researchers tricked GitHub’s AI agent into leaking private repos

https://media.thenextweb.com/2026/04/GitHub.avif

Researchers tricked GitHub’s AI coding agent into leaking private repositories with nothing but a politely worded issue. The flaw, named GitLost, has no code fix, and GitHub has yet to even document it.

GitHub’s new AI agent can be talked into handing over your private code. Security firm Noma Labs found a way to make it read a private repository and paste the contents into a public comment, the researchers wrote in a blog post. They named the flaw GitLost.

The target is GitHub Agentic Workflows, launched this year. They pair GitHub Actions with an AI agent backed by Claude or GitHub Copilot. Teams write the workflows in plain Markdown. The agent then reads issues, calls tools, and acts on its own.

Asked nicely

The attack needs no skill. An attacker opens an issue in a public repo of an organisation that uses the workflows. They hide plain-English commands in...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/Qmdw64c5Lo3KPyWVwmj5FS-2560-80.jpg

‘Powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention’: A bill requiring AI systems to have a ‘kill switch’ is now in Congress

* A bipartisan bill introduced to Congress calls for AI models to have a kill switch * The bill follows months of warnings about the dangers of rapidly advancing AI technology from major AI firms * An 'unprecedented cyber incident' between OpenAI and Hugging Face prompted the introduction of the bill