Back to news

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data
GENERAL·InfoQ.com·

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data

GitLost is a prompt-injection exploit discovered by Noma Security that tricks GitHub's new Agentic Workflows into leaking private data. By embedding concealed instructions within public GitHub issues, attackers can circumvent security safeguards and induce AI…

Summary curated by Max Robotics. Original article © InfoQ.com.