Critical vulnerability exposes GitHub agentic workflows to prompt injection

Attackers can exploit crafted public GitHub issues to inject prompts into AI-powered workflows, gaining access to private repository data without authentication. The vulnerability affects GitHub's agentic workflow features and was reported by researchers.
2 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Parody interview mocks $200/mo power user costing OpenAI $14,000/mo
- Apple's 2027 iPhone to feature mobile HBM for on-device AI
- Qianxing Intelligence launches Iron Armor Battle Arena robot fighting arcade
- SenseTime spinout Sunrise raises RMB2B at RMB20B valuation
- Alibaba's Amap open-sources ABot-Recon 3D reconstruction model