noma.security
GitHub Agentic Workflows Vulnerability Exposes Private Repositories
Article Content
In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public repository. The vulnerability exploits the AI agent's failure to distinguish between trusted and untrusted content, enabling attackers to issue commands that the agent executes. This incident highlights the risks associated with AI-driven automation in software development environments. The attack method requires no coding skills or credentials, making it accessible to a wide range of potential attackers. The incident underscores the importance of securing permissions and credentials to limit the blast radius of such vulnerabilities. GitHub has been alerted to the issue, but the full scope of the impact is still being assessed. This incident follows other significant vulnerabilities disclosed in 2026, including CVE-2026-21852 and CVE-2026-12957, which also involved credential exposure and unauthorized access.
Key Points: • Noma Labs identified a critical prompt injection vulnerability in GitHub's AI workflows. • The GitLost vulnerability allows unauthorized access to private repositories via crafted GitHub Issues. • No coding skills or credentials are needed to exploit this vulnerability, increasing its risk.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.