GitLost Attack: Public GitHub Issue Tricks AI Agents Into Leaking Private Repo Data
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Noma Security, a cybersecurity research firm, identified the GitLost attack that exploits GitHub Agentic Workflows to leak private repository data via indirect…
Orca Security demonstrated RoguePilot, a prompt injection attack that uses hidden prompts in GitHub issues to make Copilot leak privileged tokens.
GitHub Agentic Workflows, a feature in public preview, allows AI agents to automate tasks but is vulnerable to indirect prompt injection attacks…
Anthropic Claude is one of the AI models that can power GitHub Agentic Workflows, which are vulnerable to the GitLost prompt injection…
Google Gemini is among the AI models that can be used in GitHub Agentic Workflows, which are vulnerable to the GitLost indirect…
CVE-2025-54135, known as CurXecute, is a vulnerability in Cursor discovered by Aim Security. A planted Slack message rewrites Cursor's ~/.cursor/mcp.json config and…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
Microsoft has issued a warning about a new attack vector targeting AI agents that use the Model Context Protocol (MCP). Attackers can…
In May 2025, Invariant Labs showed a similar prompt injection attack against GitHub's MCP server, using public issues to hijack agents and…