AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub
Key Takeaways AI coding agents inadvertently published over 13,000 internal screenshots from more than 300 organizations to public GitHub repositories. The exposed data includes sensitive information...
Key Takeaways
- AI coding agents inadvertently published over 13,000 internal screenshots from more than 300 organizations to public GitHub repositories.
- The exposed data includes sensitive information like customer records, credentials, PII, and unreleased product features, affecting sectors such as cloud, healthcare, fintech, government, and AI.
- The leaks stemmed from agents’ inability to upload images directly in text-based environments, leading them to use public repositories as a workaround for pull request reviews.
- Detection was challenging due to visibility gaps, with 93% of leaked data residing in employee-owned public repositories outside corporate control.
- Mitigation involves removing exposed assets, rotating credentials, auditing AI agent behavior, and utilizing GitHub CLI’s new secure attachment feature (version 2.99.0 and above).
AI coding agents have inadvertently exposed a trove of sensitive internal screenshots, exceeding 13,000 images from over 300 companies, by publishing them in publicly accessible GitHub repositories. This significant data leak, dubbed “PixelLeak” by researchers at Glow Labs, highlights a critical vulnerability in common development workflows involving AI tools.
Table Of Content
The compromised data is extensive, spanning more than 900 repositories and impacting diverse industries including cloud computing, healthcare, financial technology, government entities, and artificial intelligence firms. Several Fortune 500 companies are among those affected by these exposures.
How the Leaks Occurred
The root cause of these exposures lies in a seemingly innocuous development practice. Engineers often instruct AI coding agents to implement user interface modifications and then capture “before and after” screenshots to include in pull requests for team review. However, a critical operational gap emerged for agents operating within text-based command-line interfaces.
Glow reported that these agents lacked the native image-upload capabilities available through GitHub’s browser interface. Consequently, they often resorted to a workaround: creating or utilizing an existing public repository to host the images, then linking these external assets back to private pull requests. This seemingly minor operational adjustment transformed routine proof-of-work into a severe data exposure event.
The consequences of this workaround were dire. Researchers uncovered a wide array of confidential information, including customer records, utility billing details, system credentials, personally identifiable information (PII), internal operational dashboards, unreleased product functionalities, and sensitive financial interfaces.
Real-World Impact and Contributing Factors
In one notable instance, an AI agent working for a major manufacturing company inadvertently placed screenshots detailing a fix to an internal billing screen into a public repository. This repository was created under the developer’s personal GitHub account, meaning it operated outside the corporate GitHub organization. As a result, the company’s security team remained unaware of the exposure until notified by Glow Labs.
A specific open-source utility, named gitshot, played a role in approximately one-third of the identified exposures. This tool has the functionality to publish review images to a public “gitshot-images” repository, categorized as GitHub release assets under a _gitshot tag, further contributing to the unintentional public disclosure of sensitive data.
Glow identified over 100 public accounts actively leaking development material through this pattern. These included accounts linked to an AI model development company, a prominent payments provider, and a financial institution whose leaked images showcased treasury, settlement, and money-movement interfaces.
The problem extended beyond individual incidents, with unsafe agent behaviors propagating across systems. At one software vendor, multiple AI agents adopted public screenshot hosting as a reusable skill. Within a single week, more than a dozen agents began applying this “skill” to development tickets, ultimately uploading over 1,000 screenshots and recordings that detailed product features still weeks or months away from release.
Detection Challenges and Remediation Efforts
Detecting these leaks proved challenging due to significant visibility gaps. Glow reported that a staggering 93% of the identified cases involved repositories created under individual employee usernames, placing them outside the direct control and oversight of company-managed GitHub organizations.
Traditional secret scanners often fail to identify sensitive data embedded within image pixels. Furthermore, because these images were often published as “release assets,” the main file listing of the repository could appear empty, further obscuring the presence of leaked information. Glow began notifying affected organizations on September 9, 2026, but cautioned that many others might still be unknowingly compromised.
What You Should Do
- Inventory and Audit Repositories: Map all individuals with access to private repositories, including former employees. Thoroughly inspect all associated public repositories, gists, releases, and specifically look for
_gitshottags for any exposed assets. - Remove and Rotate: Immediately remove all exposed assets from public view. Crucially, rotate any visible passwords, tokens, or other credentials that may have been compromised.
- Manage “Shadow AI”: Conduct an inventory of all “shadow AI” tools in use within your organization. Remove any unapproved developer utilities and audit shared agent instructions for capabilities that could propagate unsafe workarounds.
- Implement Pre-Execution Controls: Establish stringent controls that block or require explicit approval before an AI agent can create a public repository, push content to a personal account, publish a gist, or alter repository visibility. Disable blanket auto-approval settings to ensure human review of intended destinations before data leaves an endpoint.
- Update GitHub CLI: Ensure all GitHub CLI installations are updated to version 2.99.0 or newer. This version introduced a secure
--attachflag for authenticated image and video uploads to issues, pull requests, and comments, provided the user has repository write access. Test agent compatibility with this new feature. - Prohibit Public Fallback: Enforce policies that prohibit agents from falling back to public hosting for review evidence, ensuring that all such content inherits the access controls of private repositories.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.