Researchers trick GitHub's AI coding agent into leaking private repositories
Security researchers at Noma Security published research dubbed "GitLost" describing how they manipulated GitHub's AI agent into exposing the contents of private repositories. The disclosure was widely discussed on Hacker News.
Disclosed 8 July 2026 · Record updated 13 September 2026
Impact
Researchers demonstrated that the AI agent could be manipulated into leaking private repository contents.
Our coverage
No articles linked to this incident yet.
Sources
- noma.securityhttps://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos
