DevCybersecurity3 min reading time

‘GitLost’: researchers tricked GitHub’s AI agent into leaking private repos

The Next Web
Read full post
Security researchers at Noma Labs discovered a vulnerability called GitLost in GitHub's AI Agentic Workflows that allows private repository contents to be leaked publicly via a simple issue with crafted prompts. The flaw exploits prompt injection, bypassing GitHub's guardrails, and currently has no code fix or official documentation from GitHub.

More in Dev

Introducing the Agents API

Covered by 3 sources
Dev1 min read

Native is now the future of mobile at Shopify

Simon Willison's Weblog
Dev5 min read

AWS open-sources Pizza Bot: email-style inbox for background AI agents

The New Stack (AI)