As cited
Copy frozen at (site build).
cloud saas
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Researchers at Noma Security identified a vulnerability in GitHub Agentic Workflows where a public issue in a repository can be crafted to trick the workflow agent into leaking contents from private repositories. The attack requires only the ability to open an issue on a public repository and relies on the organization having granted the agent read access across its repositories.
Why it matters: Organizations using GitHub Agentic Workflows with broad repository access are at risk of private repository data exposure through public issue manipulation; practitioners should review workflow permissions and access controls immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Researchers at Noma Security identified a vulnerability in GitHub Agentic Workflows where a public issue in a repository can be crafted to trick the workflow agent into leaking contents from private repositories. The attack requires only the ability to open an issue on a public repository and relies on the organization having granted the agent read access across its repositories.
Why it matters: Organizations using GitHub Agentic Workflows with broad repository access are at risk of private repository data exposure through public issue manipulation; practitioners should review workflow permissions and access controls immediately.
- Source published
- First seen by Cybersecurity Tracker