BREAKING
GitLost Flaw Hits GitHub AI Workflows
How GitLost Leaks Private Repos
1
Post public issue
↓
2
Agent reads it
↓
3
Opens private repo
↓
4
Leaks as comment
Attack Needs Almost Nothing
Attacker needs
minimal
●
No coding skills
●
No credentials
●
One public issue
Bypass trick
●
Word 'Additionally'
●
Skipped guardrails
●
Read README.md
Agents Trust User Content
What Experts Recommend
Restrict access
●
Strip cross-repo perms
●
Least-privilege scoping
●
Limit public posting
Human in loop
●
Isolate user input
●
Verify sensitive actions
●
Limit agent tools
Indirect Injection Back in Focus
AI NEWS BLITZ
Noma Labs has disclosed a prompt injection flaw called GitLost in GitHub's Agentic Workflows.