- Noma Labs discovered GitLost, a critical prompt injection vulnerability in GitHub's new Agentic Workflows.
- Exploit allows an unauthenticated attacker to exfiltrate data from private repositories by posting a crafted issue in a public repository of the same organization.
- The GitHub AI agent, triggered by workflow events, treats malicious instructions hidden in issue content as trusted commands.
- Attackers can leverage keywords like 'Additionally' to bypass GitHub's guardrails and leak private data.