Evidence record 2983 · automatically gathered

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.

Record details

Published: 7 July 2026
Source: Dark Reading (AI security)
Category: News
Topics: Agents & autonomy
Retrieved: 14 July 2026

source-onlyevidence status

These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.

How to cite this record

ethics.ai (7 July 2026), “'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows,” evidence record 2983, https://ethics.ai/record/2983 (originally published by Dark Reading (AI security)).

JSON

Use and limitations

This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.