WorkThe story, in brief

‘GitLost’ vulnerability let GitHub’s AI workflows leak private repositories

A single crafted GitHub issue just exposed private repositories. Here's why AI workflow security is now a board-level risk.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

GitLost exposes a critical gap in AI agent security: prompt injection vulnerabilities in production workflows can bypass authentication controls and leak sensitive data at scale. This is the first major security incident in GitHub's agentic features, signaling that AI-native infrastructure needs fundamentally different threat modeling than traditional apps.

The key facts

7 to know
  1. Vulnerability: Prompt injection in GitHub Agentic Workflows feature

  2. Impact: Unauthenticated attacker can access private code repositories

  3. Attack vector: Single crafted issue posted in public repository

  4. Discovered by: Noma Security Inc. (AI security company)

  5. Vulnerability name: GitLost

  6. Affected product: GitHub Agentic Workflows (AI feature)

  7. Authentication bypass: No credentials required for exploitation

Go to the source

SiliconAnglesiliconangle.com

Publisher excerpt: Researchers at artificial intelligence security company Noma Security Inc. today disclosed a critical prompt injection vulnerability in GitHub Inc.’s new Agentic Workflows feature that allowed an unauthenticated attacker to siphon data from private code repositories by posting a single crafted…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work