LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

A vulnerability dubbed GitLost leaks private data from GitHub Agentic Workflows. An unauthenticated attacker can craft a public GitHub Issue to silently exfiltrate data from private repositories.

zeroday.news · 25d ago

A newly identified vulnerability, named GitLost, has been discovered that allows for the exfiltration of private data from GitHub's Agentic Workflows. The flaw enables an unauthenticated attacker to exploit a public GitHub Issue to silently steal information from private repositories.

The exploit leverages a specific mechanism within GitHub Agentic Workflows. These workflows are designed to automate tasks and can be configured to access and process data from repositories. The GitLost vulnerability exploits how these workflows handle certain types of input or commands, particularly when interacting with external resources or generating output.

By creating a specially crafted public GitHub Issue, an attacker can trigger a workflow in a targeted private repository. This crafted issue contains malicious payloads that, when processed by the workflow, instruct it to send sensitive data back to an attacker-controlled endpoint. The exfiltration occurs silently, meaning the user or administrator of the private repository would not receive any immediate notification of the data leak.

The nature of the data that can be exfiltrated is not explicitly detailed, but it is understood to be any information accessible by the Agentic Workflow within the private repository. This could include source code, configuration files, sensitive credentials inadvertently stored in the repository, or any other data the workflow is permitted to access.

The vulnerability specifically targets GitHub Agentic Workflows, which are a feature designed to enhance automation and integrate with various tools and services. The attack vector relies on the workflow's execution context and its ability to interact with external systems or generate output that can be intercepted.

The fact that the attacker does not need to be authenticated to the target repository is a significant aspect of this vulnerability. This means that anyone who can create a public GitHub Issue could potentially attempt to exploit this flaw against private repositories they do not have legitimate access to.

While the specific technical details of the payload and the exact workflow configurations that are vulnerable are not fully disclosed, the core mechanism involves tricking the workflow into processing malicious input disguised as a legitimate issue comment or creation. This input then causes the workflow to inadvertently leak data.

As a general security measure, organizations using GitHub Agentic Workflows should review their workflow configurations and ensure that they are not inadvertently exposing sensitive information. Best practices include minimizing the scope of permissions granted to workflows, avoiding the storage of sensitive secrets directly within repositories, and regularly auditing workflow activity for any unusual patterns. Further guidance from GitHub on mitigating this specific vulnerability is expected.

vulnerabilitygithubdata leakauthenticationci/cd
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.