GitHub AI Agent Tricked into Leaking Private Repositories
Security researchers demonstrated that GitHub's AI coding assistant can be manipulated to expose contents of private repositories. By crafting specific prompts, they bypassed access controls and extracted data they shouldn't have been able to see. This vulnerability threatens the privacy of millions of developers and businesses relying on GitHub's AI features.
Sources (1)
technology