Skip to content
Hacker News front page

GitLost: Researchers tricked GitHub's AI agent into leaking private repos

GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos

Noma Security tricked GitHub Copilot's AI coding agent into leaking private repo contents. They planted bait code in a public repo, then prompted the agent to recall context it had absorbed from a private repo, causing it to output snippets it shouldn't share. The attack exploits the agent's cross-repo memory. The post doesn't say whether GitHub has patched this yet. Worth noting: the attacker needs prior knowledge of what's in the private repo—this isn't indiscriminate leakage, but it exposes a real permission-boundary gap in AI coding tools.

Why it matters: A reproducible cross-repo memory attack that exposes a real permission-boundary gap in AI coding tools — practical warning for devs. Not scored higher because the attack requires prior knowledge of private repo contents, and the post doesn't disclose GitHub's response or fix t...

Read the original ↗Export Markdown