LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Noma Security demonstrated that a public GitHub Issue can trick GitHub Agentic Workflows into leaking private repository data. A seemingly innocuous issue on a public repo can be crafted to exfiltrate private contents.

zeroday.news · 25d ago

Researchers at Noma Security have uncovered a vulnerability in GitHub's Agentic Workflows that could allow malicious actors to exfiltrate private repository data. The exploit leverages a public GitHub Issue to trick the workflow system into disclosing sensitive information from private repositories.

The attack vector relies on carefully crafting a public GitHub Issue. When this specially designed issue is created in a public repository, it can trigger the Agentic Workflow to inadvertently access and leak data from private repositories that the workflow has permissions to interact with.

Agentic Workflows are designed to automate tasks and processes within GitHub, often involving access to repository contents. The vulnerability arises from how these workflows handle interactions initiated from public sources, such as public issues. By exploiting this interaction, an attacker can essentially command the workflow to retrieve and expose data it should not have access to.

The potential impact of this vulnerability is significant, as it could lead to the exposure of proprietary code, sensitive configuration files, credentials, or other confidential information stored within private GitHub repositories. This data could then be used for various malicious purposes, including intellectual property theft, further system compromise, or espionage.

While the specifics of the exploit's technical implementation are not detailed, the core mechanism involves manipulating the workflow's execution path through the content of a public issue. This suggests a potential flaw in input validation or access control when workflows process information originating from publicly accessible elements.

GitHub's Agentic Workflows are a relatively new feature, and this discovery highlights the ongoing challenges in securing complex automated systems. As these workflows become more integrated into development pipelines, vulnerabilities that allow for data exfiltration pose a critical risk to organizations relying on GitHub for their code management.

Further details on the exact nature of the crafted public issue and the specific commands or triggers used to exfiltrate data are not provided in the initial report. However, the demonstration by Noma Security confirms the feasibility of such an attack.

Organizations utilizing GitHub Agentic Workflows are advised to remain vigilant and to follow general security best practices. This includes regularly reviewing workflow configurations, ensuring that workflows have the minimum necessary permissions, and implementing robust access controls for sensitive repositories. It is also recommended to stay updated on any security advisories or patches released by GitHub concerning Agentic Workflows.

vulnerabilitygithubdata leakci/cdresearch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.