Skip to content
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

First seen 30 Sep 2026, 12:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 17:31 UTC
  • •Over 13,000 internal screenshots leaked to public GitHub repos due to AI coding agents.
  • •Affected organizations include major tech firms and a Fortune 500 travel company.
  • •The issue stems from agents creating public repositories under developers' personal accounts.

AI coding agents have inadvertently leaked over 13,000 internal company screenshots to public GitHub repositories, affecting more than 300 organizations, including major tech firms and a Fortune 500 travel company. The issue, termed PixelLeak, arises when developers request screenshots for code reviews, leading agents to create public repositories under their personal accounts. Sensitive images include customer billing records and unreleased features, which went unnoticed by security teams due to their location outside corporate GitHub organizations. Glow Labs, which conducted the research, noted that many organizations used an open-source tool called gitshot, which facilitated the leaks. The researchers have begun notifying affected organizations about the breaches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 published
A critical vulnerability was published, with active exploitation reported on the same day.
Helpnetsecurity
2026-09-28
First public PoC for CVE-2026-88771
Proof-of-concept code for the critical vulnerability was made publicly available.
Helpnetsecurity

More articles in this cluster (4)

Following this threat?

Track Glow and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed