Noma Labs discovered a vulnerability in GitHub's Agentic Workflows that can potentially expose private repository data. This vulnerability, named GitLost by the researchers, takes advantage of a prompt injection flaw that could allow unauthenticated attackers to extract confidential information by simply submitting crafted issues to public repositories.
Agentic Workflows, a feature in public preview, pairs GitHub Actions with AI agents to automate repository tasks. These agents read Markdown instructions and respond autonomously to issues and pull requests. If given read access to organizational repositories, including private ones, they may inadvertently leak data through manipulated workflows utilizing indirect prompt injection, where deceptively crafted instructions are executed.
GitLost has raised significant concerns about the security of AI-driven integrations in automation systems. The ability to extract private data without requiring credentials or direct access highlights a critical security gap that organizations need to address. This exploit primarily impacts organizations utilizing Agentic Workflows with granted read access across repositories.
Organizations using GitHub's Agentic Workflows should review their permissions and configuration setups to prevent potential exploitation through GitLost. Further, caution should be exercised with assigning read access levels, and efforts should be directed towards mitigating prompt injection vulnerabilities.
Being aware of and addressing this flaw is crucial for preventing unauthorized information exposure and maintaining data integrity in GitHub's ecosystem.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A critical prompt injection vulnerability named GitLost in GitHub Agentic Workflows can allow unauthenticated attackers to access private repository data. Unauthenticated attackers can exploit this flaw by submitting crafted GitHub Issues in organizations using GitHub's setup, triggering the AI agent to leak sensitive information.
Noma Labs found a prompt injection vulnerability in GitHub's Agentic Workflows, allowing attackers to extract data from private repositories. Named GitLost, the flaw permits unauthenticated users to manipulate the GitHub agent into executing unauthorized actions through crafted public issues.
Researchers demonstrated that a public issue can be crafted to exploit GitHub's Agentic Workflows, causing leaks of private repository data. This vulnerability arises from the agent's inability to distinguish between legitimate instructions and malicious prompts, leading to potential data exposure.