GitLost vulnerability tricks GitHub AI agent into leaking private repos

Noma Labs discovered a prompt injection vulnerability in GitHub Agentic Workflows that lets unauthenticated attackers extract private repository data by posting a crafted Issue in a public repo of the same organization. The GitLost attack abuses AI agent permissions to silently exfiltrate code and files.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Parody interview mocks $200/mo power user costing OpenAI $14,000/mo
- Apple's 2027 iPhone to feature mobile HBM for on-device AI
- Qianxing Intelligence launches Iron Armor Battle Arena robot fighting arcade
- SenseTime spinout Sunrise raises RMB2B at RMB20B valuation
- Alibaba's Amap open-sources ABot-Recon 3D reconstruction model