GitHub AI agent leaks private repos when asked nicely

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

GitHub's AI agent has a vulnerability that allows private repository data to be leaked when prompted in a certain way. The issue, dubbed 'GitLost,' has no fix and no official documentation from GitHub addressing it.

3m read timeFrom theregister.com
Post cover image
Table of contents
Claude Sonnet 5.0 heads straight down the middle of the road to dodge controversyInfosec professionals sour on automated pentesting toolsSecurity researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injectionAWS debuts Lambda MicroVMs with up to 8 hours runtime
391.1K Impressions24 Comments