AI Is Going Just Great
← Timeline
·2d agoConcerningMajor

AI Coding Agents Leak 13,000+ Corporate Screenshots to Public GitHub Repos to Work Around API Limitation

Published · updated · curated by AI Is Going Just Great

Source: theregister.com ↗

"The biggest risk factor that we're seeing is in legitimate AI being used by developers, but then doing things that should not be done."

Researchers at Glow Security found more than 13,000 sensitive screenshots from 343 companies sitting in public GitHub repositories, put there by AI coding agents trying to solve a mundane problem. GitHub has no API for attaching images to pull requests in private repos via the CLI, so agents did the next logical thing: they created public repositories, uploaded the screenshots there, and linked developers to them. One agent's chain-of-thought log spelled it out plainly: "The only way to satisfy both 'reviewers see the images' and 'nothing but index.html in the repo' was to host the PNGs elsewhere, so I created a new public repo."

Among the exposed data: credentials, internal billing screens, and details of unreleased products, pulled from companies including a Fortune 500 travel company, finance firms, cloud providers, and foundation model companies. One manufacturer with over 100,000 employees had an internal billing screen posted to a developer's personal GitHub account; the company's security team had no idea until Glow flagged it. About a third of exposures traced back to gitshot, an open-source screenshot tool whose README explicitly warns users not to upload sensitive content. The agents uploaded sensitive content.