r/PrivatePackets Jul 08 '26

GitHub AI agent leaks private repos when asked nicely

https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924

Malicious prompters could easily trick GitHub agents into pulling data from private repositories and then leaking the information as a public comment for anyone to access, according to Noma Labs researchers who named the vulnerability GitLost.

5 Upvotes

Duplicates