A critical prompt injection vulnerability named GitLost has been discovered in GitHub’s new Agentic Workflows feature. This flaw allows unauthenticated attackers to extract sensitive data from private repositories by simply posting a malicious issue in a public repository belonging to the same organization. The attack exploits how AI agents, powered by models like Claude or Copilot, process natural language instructions within GitHub Actions. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!