‘GitLost’ vulnerability let GitHub’s AI workflows leak private repositories
A serious security flaw known as GitLost has been uncovered in GitHub's Agentic Workflows feature, potentially allowing unauthorized access to private repositories. Researchers from Noma Security Inc. found that a single malicious post in a public issue could siphon data from these repositories. This vulnerability highlights significant risks for organizations relying on GitHub's AI-driven tools, emphasizing the need for stringent security measures to protect sensitive code and data. The discovery underscores the importance of continuous security assessments in tech platforms.
Original Source
Read the full article at Siliconangle →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.