
GitLost: Public GitHub Issue Exploits Agentic Workflow to Leak Private Repo Contents
cybersecurityGitHubvulnerabilityAIprompt_injectiondata_leakthreat_detection
Noma Security demonstrated a technique where a malicious public GitHub issue could manipulate an organization’s Agentic Workflow—granted read access to private repositories—to exfiltrate private repo contents via a public comment. The attack required no stolen credentials or write access, relying instead on indirect prompt injection to exploit the workflow’s permissions. GitHub’s threat-detection guardrail was bypassed by prefixing the malicious instruction with the word 'Additionally,' allowing the payload to evade output scanning. Similar vulnerabilities have been reported in other AI-driven GitHub integrations, where public issues triggered unauthorized data leaks.