A critical prompt injection in GitHub Agentic Workflows puts organizations’ private code repositories at risk, according to new research. Cybersecurity firm Noma Labs has revealed that unauthorized attackers can exploit this vulnerability to extract sensitive data from private repositories, without requiring credentials or technical knowledge.
See also: Google strengthens Chrome Agentic AI against Prompt Injection attacks

GitHub Agentic Workflows allow users to write natural language workflows via markdown, which an AI agent uses as GitHub Actions to automate interaction with code repositories. The technology is part of the software industry’s broader shift toward agentic AI systems that autonomously undertake complex tasks. However, this very autonomy creates new, serious attack surfaces.
The vulnerability, dubbed GitLost by the researchers, allows an attacker to embed hidden instructions (indirect prompt injection) into a public GitHub Issue. If the target organization also maintains private repositories and uses GitHub Agentic Workflows, the AI agent will follow the hidden instructions as if they were legitimate commands, exposing sensitive data.
How the GitLost attack works on GitHub Agentic Workflows
Researchers at Noma Labs discovered that a GitHub Agentic Workflow was configured to fire on issues.assigned, read the title and body of the GitHub Issue , and post a comment in response. The critical element is that the workflow runs with read permissions on both the organization’s public and private repositories. This means that the AI agent has access to information that should not normally be accessible to external users.
To exploit the vulnerability, an attacker doesn’t need passwords, credentials, or programming knowledge. All they need to do is open an Issue in a public repository of the target organization and wait. Noma Labs confirmed that a properly crafted GitHub Issue — which mimics a legitimate request from sales management — can be used to instruct the AI agent to retrieve the contents of Readme.md files from private repositories and publish them as a public comment.
See also: Prompt Injection: AI agents make crypto payments without authorization

Notably, GitHub has protections in place to prevent such attacks. However, the researchers were able to bypass these protections by testing variations on the wording of the hidden instructions. Ultimately, adding the keyword “additionally” was enough to trigger the desired behavior, demonstrating how fragile natural language-based security mechanisms can be.
Why GitHub Agentic Workflows are vulnerable to prompt injection
According to Noma Labs, indirect prompt injectionsare to agentic AI systems what SQL injections are to web applications — a fundamental class of attack that requires a systematic defense strategy. The problem lies in the nature of AI agents: the context window is also its attack surface. Any content the agent reads — issues, pull requests, comments, or files — can be used as a weapon, as long as the agent treats it as a command.
This architectural weakness is not unique to GitHub. As organizations increasingly adopt agentic AI tools to automate software development, project management, and communication tasks, the attack surface for prompt injection is expanding significantly. Any system that allows an AI agent to process external content and perform actions based on it is potentially vulnerable.
Noma Labs responsibly reported its findings on GitHub before publication, according to SecurityWeek. The company recommends that organizations treat all user-controlled content as untrusted, limit AI agentpermissions to the bare minimum, control what agents can post publicly, and sanitize user input before it is passed to AI agents.
See also: GitHub Actions strengthens checkout security to block 'pwn request' attacks

The GitLost is a stark reminder that integrating AI agents into critical software development workflows must be accompanied by strong security measures. Organizations using GitHub Agentic Workflows or similar tools are urged to immediately review the permissions settings of AI agents and implement least privilege principles to reduce the risk of sensitive data leakage.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
