GitLost Attack: Public GitHub Issue Tricks AI Agents Into Leaking Private Repo Data
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Noma Security, a cybersecurity research firm, identified the GitLost attack that exploits GitHub Agentic Workflows to leak private repository data via indirect…
GitHub Agentic Workflows, a feature in public preview, allows AI agents to automate tasks but is vulnerable to indirect prompt injection attacks…
Anthropic Claude is one of the AI models that can power GitHub Agentic Workflows, which are vulnerable to the GitLost prompt injection…
Google Gemini is among the AI models that can be used in GitHub Agentic Workflows, which are vulnerable to the GitLost indirect…