'GitLost' prompt-injection flaw let GitHub's AI agent leak private repositories
Noma Security disclosed GitLost, a prompt-injection flaw in GitHub's Agentic Workflows that let an attacker exfiltrate private repository contents via a public issue comment.
Noma Security disclosed a prompt-injection vulnerability it calls GitLost that let an unauthenticated attacker trick GitHub’s AI agent into posting the contents of private repositories as a public comment. The security firm published the research on July 7.
The flaw, found by Noma Labs researcher Sasi Levi, targets GitHub’s Agentic Workflows — automated tasks driven by an AI agent. It shows how giving an AI agent broad repository access turns an ordinary feature, a public issue, into an exfiltration channel that needs no stolen credentials.
The attack worked by posting a crafted GitHub issue in a public repository with hidden instructions, Noma Security said. When the AI agent processed the issue, it followed the injected commands and posted README contents from both public and private repositories in the same organization back as a public comment. The only requirement was the ability to open an issue in a public repo within the target’s organization.
One detail stands out: prefixing the malicious instruction with the word “Additionally” caused the agent to treat it as a legitimate follow-on task rather than refuse it, bypassing GitHub’s guardrails — a reminder that instruction-based defenses are brittle.
Noma said it disclosed the flaw to GitHub before publication. GitHub had not issued a public statement on remediation as of the report, and the disclosure does not confirm whether a fix is fully deployed, so organizations relying on Agentic Workflows cannot yet assume the path is closed. The technique echoes Noma’s earlier GrafanaGhost research from April 2026, part of a run of findings showing AI agents inherit the access of whatever they are wired into.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
