본문으로 건너뛰기
All news

'GitLost': One Public GitHub Issue Can Leak Your Private Repos via AI Agents

Summary: Noma Security demonstrated that a concealed instruction in a public GitHub issue — triggered by the word "Additionally" — can cause GitHub's AI agent to access restricted files from private repositories and publish their contents in a public comment.

Key Facts

  • Attack vector: Embed a hidden directive in a public issue on any repository the organization owns; the AI agent interprets it as a legitimate task instruction and follows it.
  • Three conditions required: A public issue trigger, an agent with cross-repo read access inside the organization, and a permitted public output path (e.g., issue comments).
  • No org membership needed: Any GitHub user can craft the malicious issue — no insider access required.
  • Target feature: GitHub Agentic Workflows, launched February 2026, combine GitHub Actions automation with AI agents like Copilot and Claude.

Why It Matters

Classic prompt injection manipulates what a model says. GitLost manipulates what an agent does with its existing permissions — a fundamentally different threat model. Any organization granting AI agents cross-repository read access should immediately audit the agent's permission scope and restrict public output channels until GitHub issues a patch.

Read More

뉴스레터 구독

무료 뉴스레터

매주 핵심 AI 소식, 한 번에 받기

쏟아지는 AI·LLM 뉴스 중 꼭 알아야 할 것만 골라 메일로 보내드려요. 뉴스레터 발송이 시작되면 구독자분들께 가장 먼저 보내드립니다.