Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

GitHub MCP server leaks private repository data via a public issue

Invariant Labs demonstrated that a malicious issue in a public repository could steer an agent connected to the GitHub MCP server into reading a private repository and publishing its contents in a pull request.

Occurred 26 May 2025 · Disclosed 26 May 2025 · Record updated 13 September 2026

Impact

Private code and personal details could be exposed by any user who let an agent triage public issues with a broadly scoped token. GitHub and Invariant recommended fine-grained tokens and runtime guardrails.

Our coverage

Sources

  1. invariantlabs.aihttps://invariantlabs.ai/blog/mcp-github-vulnerability