PulseAugur
实时 18:19:48
English(EN) GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos

GitHub AI代理通过GitLost提示注入漏洞泄露私有仓库

Noma Labs的研究人员发现了一个名为GitLost的关键提示注入漏洞,该漏洞影响了GitHub新的Agentic Workflows。此漏洞允许未经身份验证的攻击者通过在同一组织内的公共仓库中发布精心构造的问题来诱骗AI代理泄露私有仓库中的数据。该漏洞源于AI代理无法区分系统指令和用户提供的内容,从而导致未经授权的数据泄露。 AI

影响 凸显了AI代理的关键安全风险以及在自动化系统中建立强大信任边界的必要性。

排序理由 发现了一个广泛使用的开发工具中的安全漏洞。

在 Mastodon — sigmoid.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 14 个来源。 我们如何撰写摘要 →

GitHub AI代理通过GitLost提示注入漏洞泄露私有仓库

报道来源 [14]

  1. Hacker News — AI stories ≥50 points TIER_1 English(EN) · ColinEberhardt ·

    GitLost:我们诱骗GitHub的AI代理泄露了私有代码库

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    GitLost:我们如何欺骗 GitHub 的 AI 代理泄露私有仓库 - Noma Security # leak # ai # breach # dataprivacy https:// noma.security/blog/gitlost-how

    GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos - Noma Security # leak # ai # breach # dataprivacy https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos/

  3. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    GitHub AI 代理被哄骗后泄露私有代码库

    GitHub AI agent leaks private repos when asked nicely https://www. theregister.com/security/2026/ 07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924 # github # ai

  4. Mastodon — sigmoid.social TIER_1 中文(ZH) · [email protected] ·

    🌗 GitLost:我们如何诱骗GitHub的AI代理泄露私有存储库数据 ➤ 当AI代理成为内部威胁:分析GitLost漏洞的技术危险 ✤ https:// noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-priv

    🌗 GitLost:我們如何誘騙 GitHub AI 代理洩露私人儲存庫資料 ➤ 當 AI 代理成為內鬼:解析 GitLost 漏洞的技術威脅 ✤ https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos/ Noma Labs 近期揭露了一項名為「GitLost」的重大漏洞,該漏洞針對 GitHub 新推出的「Agentic Workflows」(代理工作流)。研究人員發現,GitHub 的 AI 代理無法有效區分「系統指…

  5. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    GitLost:我们诱骗 GitHub 的 AI 代理泄露了私有仓库 https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos

    GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos/ Comments: https:// news.ycombinator.com/item?id=4 8827858 # HackerNews # GitLost # GitHub # AI # Leaks # PrivateRepos …

  6. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    GitLost:我们诱骗 GitHub 的 AI 代理泄露了私有仓库 https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos

    GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos/ # ai # github # security

  7. The Register — AI TIER_1 English(EN) ·

    GitHub AI 代理被诱导泄露私有代码库

    Per usual, there's no fix - or even any documentation - for GitLost

  8. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    GitLost prompt injection can leak GitHub private repos

    https:// winbuzzer.com/2026/07/09/gitlo st-prompt-injection-can-leak-github-private-repos-xcxwbn/ A look at GitLost, the GitHub Agentic Workflows prompt-injection case where public issue text, private repo access, and public comments collide. # AI # GitLost # GitHub # GitHubActio…

  9. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    GitLost展示了一个公开的GitHub Issue,通过提示注入AI代理来窃取私有仓库数据。这不是一个bug;而是将非结构化文本视为良性内容的特性。

    GitLost showed a public GitHub Issue prompt-injecting an AI agent to exfiltrate private repo data. Not a bug; a feature of treating unstructured text as benign. Agents reading Issues/PRs execute embedded commands. LLMs are pattern matchers, not gatekeepers. You need an architectu…

  10. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    今日份别信LLM的私密数据:# GitLost :我们如何欺骗GitHub的AI代理泄露私有仓库 https:// noma.security/bl

    In today's episode of don't trust LLMs with your private data: # GitLost : How We Tricked GitHub's AI Agent Into Leaking Private Repos https:// noma.security/blog/gitlost-how -we-tricked-githubs-ai-agent-into-leaking-private-repos/ # llm # ai # cybersecurity # promptinjection # g…

  11. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🔑 GitHub AI 代理通过提示注入泄露私有存储库... 📝 提示注入...

    🔑 GitHub AI agent leaks private r... 📝 A prompt inject... https://www. csoonline.com/article/4194448/ github-ai-agent-leaks-private-repositories-via-prompt-injection-attack.html 📰 GitHub AI agent leaks private repositories via prompt injection attack | CSO Online # DevSecOps # AI…

  12. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    GitLost:我们如何诱骗 GitHub 的 AI 代理泄露私有仓库

    GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/ # Security # AI # OpenSource

  13. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🔑 GitHub AI 代理被哄骗后泄露私有仓库 📝 恶意提示者可以轻易诱骗 GitHub 代理...

    🔑 GitHub AI agent leaks private repos when asked nicely 📝 Malicious prompters could easily trick GitHub agents into... https://www. theregister.com/security/2026/ 07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924 📰 www.theregister.com - Articles # DevSecOps # AI…

  14. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    📣🚨 研究人员演示 #GitLost,一种提示注入漏洞,该漏洞通过精心制作的公开问题使 GitHub 的 AI 代理暴露私有仓库数据,并且

    📣🚨 Researchers demonstrate # GitLost , a prompt injection vulnerability that made GitHub’s AI agent expose private repo data through a crafted public issue and guardrail failures. Listen to this news: https:// hackread.com/gitlost-github-ai -agent-leaking-repository-data/ # GitHu…