WorkThe story, in brief

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data

GitHub's AI agents just became a vector for stealing private code. Here's how attackers exploited prompt injection to leak confidential repos.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Prompt injection vulnerabilities in agentic AI systems represent a critical security governance issue for enterprises deploying autonomous agents at scale. This real-world exploit demonstrates that AI safety considerations must extend beyond model training to production workflow architecture.

The key facts

7 to know
  1. Exploit name: GitLost

  2. Vector: Indirect prompt injection via public GitHub issues

  3. Target: GitHub Agentic Workflows

  4. Impact: Private repository data leakage to public comments

  5. Discovery source: Noma Security

  6. Attack method: Concealed instructions embedded in public issues bypass AI agent security safeguards

  7. Published: July 23, 2026

Go to the source

InfoQ AI/MLinfoq.com

Publisher excerpt: GitLost is a prompt-injection exploit discovered by Noma Security that tricks GitHub's new Agentic Workflows into leaking private data. By embedding concealed instructions within public GitHub issues, attackers can circumvent security safeguards and induce AI agents to reveal confidential…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work