GitHub Agentic Workflows Vulnerability Exposes Private Repositories

GitHub Agentic Workflows Vulnerability Exposes Private Repositories

First seen 25 Aug 2026, 16:23 UTC Blog.Gitguardiannoma.securitywww.wiz.ioblog.checkpoint.com 67.5

Article Content

Browse articles
ThreatCluster

In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public repository. The vulnerability exploits the AI agent's failure to distinguish between trusted and untrusted content, enabling attackers to issue commands that the agent executes. This incident highlights the risks associated with AI-driven automation in software development environments. The attack method requires no coding skills or credentials, making it accessible to a wide range of potential attackers. The incident underscores the importance of securing permissions and credentials to limit the blast radius of such vulnerabilities. GitHub has been alerted to the issue, but the full scope of the impact is still being assessed. This incident follows other significant vulnerabilities disclosed in 2026, including CVE-2026-21852 and CVE-2026-12957, which also involved credential exposure and unauthorized access.

Key Points: • Noma Labs identified a critical prompt injection vulnerability in GitHub's AI workflows. • The GitLost vulnerability allows unauthorized access to private repositories via crafted GitHub Issues. • No coding skills or credentials are needed to exploit this vulnerability, increasing its risk.

Timeline

2026-01-21
CVE-2026-21852 published
Check Point Research disclosed vulnerabilities in Anthropic's Claude Code, including credential exposure.
Blog.Gitguardian
2026-02-28
First public PoC for CVE-2026-21852
Proof of concept for the vulnerabilities in Claude Code was made public, demonstrating the risks.
Blog.Gitguardian
2026-06-23
CVE-2026-12957 published
Wiz Research disclosed a vulnerability in Amazon Q Developer extension allowing unauthorized access.
Blog.Gitguardian
2026-07-01
GitLost vulnerability discovered
Noma Labs revealed the GitLost vulnerability in GitHub's Agentic Workflows, enabling data leaks.
noma.security
2026-08-25
Public disclosure of GitLost
Noma Labs published findings on the GitLost vulnerability, detailing the attack method and implications.
noma.security