// Alert

GitHub threat report

// GitHubCRITICAL

Researchers at Noma Labs disclosed GitLost, a critical prompt injection vulnerability in GitHub's Agentic Workflows that allows unauthenticated attackers to exfiltrate sensitive data from private repositories. The flaw exploits insufficient trust boundary separation between system instructions and user-controlled input in GitHub Issues. Attackers can craft malicious issue content to trick the AI agent into executing unauthorized commands and leaking private repository data as public comments.

// Get alerts for GitHub