A critical prompt injection vulnerability named GitLost has been discovered in GitHub’s new Agentic Workflows feature. This flaw allows unauthenticated attackers to extract sensitive data from private repositories by simply posting a malicious issue in a public repository belonging to the same organization. The attack exploits how AI agents,...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!