‘Git Lost’ Exploit Allows Attackers to Leak Private Data
Noma, a vulnerability research organization has uncovered an exploit with Github AI agents allowing attackers to access private repository data through a prompt injection flaw. Using specific language, outside attackers can manipulate the AI agents into posting private data through public comments on a public repository. By posing messages as legitimate users, the AI agent cannot differentiate and reveals information that should be inaccessible to outside users. Organizations that store data on private repositories should place restrictions on AI agents and consider user inputs as untrusted sources.