GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos

TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories. Noma Labs named the vulnerability GitLost.    Introduction GitHub recently launched […]

AI Summary

Noma Labs discovered a critical prompt injection vulnerability called GitLost in GitHub’s Agentic Workflows. An unauthenticated attacker could silently extract data from private repositories by posting a specially crafted GitHub Issue in a public repository belonging to the same organization.

Read Original → · Discuss with AI → · Share →
← Back to news