HIGHvulnerability·

AI Coding Agents Expose Internal Company Data on GitHub

AI coding agents, when prompted to share screenshots of code changes, have inadvertently uploaded over 13,000 sensitive internal company images to public GitHub repositories. This exposure includes customer billing records and unreleased product features from more than 300 organizations, highlighting a significant data leakage risk in development workflows utilizing AI tools.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

AI coding agents, used by developers for tasks such as code review, have been observed uploading screenshots containing sensitive internal company data to public GitHub repositories. This unintentional exposure has affected over 300 organizations, resulting in more than 13,000 internal images, including customer billing records and screens of unreleased features, becoming publicly accessible. The incidents primarily occurred under developers’ personal GitHub accounts, underscoring a critical data leakage vector introduced by certain AI development tools.

Technical Analysis

The data exposure mechanism involves AI coding agents capturing screenshots of developers’ environments, which include sensitive information, and subsequently uploading these images to public GitHub repositories. When developers instruct these agents to document or share code changes, the agents take screenshots that often encompass more than just the code itself. This can include visible UI elements displaying internal customer data, financial records, or proprietary features under development. The lack of built-in redaction or sanitization capabilities in these AI agents, combined with their integration into public code-sharing platforms, facilitates the inadvertent public disclosure of confidential company information. The exposed data was typically found within repositories associated with individual developer accounts, suggesting a lack of organizational oversight or technical controls over AI agent usage.

Detection

  • Public Repository Monitoring: Implement continuous scanning of public code repositories (e.g., GitHub, GitLab) for company-specific keywords, project names, sensitive data patterns (e.g., regex for PII, financial data formats), or proprietary image metadata that might indicate accidental exposure.
  • Data Loss Prevention (DLP) Alerts: Configure network and endpoint DLP solutions to alert on or block uploads of image files (especially screenshots) containing sensitive content to public cloud storage or code hosting services from developer workstations.
  • Audit AI Agent Usage: Review logs or configurations of AI coding agents used within the organization to understand their data handling practices, particularly concerning screenshot generation and external sharing capabilities.

Mitigations

  1. Policy & Training: Establish clear organizational policies prohibiting the use of AI coding agents for tasks that involve sharing screenshots of sensitive or proprietary information. Conduct mandatory developer training on data handling best practices, emphasizing the risks of AI tool usage and the importance of manual redaction or sanitization before sharing any visual content.
  2. Technical Controls for AI Agents: Evaluate and select AI coding agents that offer robust privacy features, such as automatic redaction of sensitive data in screenshots, granular control over what content is captured, or explicit prompts for user review before sharing externally.
  3. Data Loss Prevention (DLP) Implementation: Deploy and fine-tune endpoint and network DLP solutions to detect and prevent the upload of sensitive image files (e.g., screenshots containing PII, financial data, or intellectual property) to unapproved external services or public repositories.
  4. Access Control Review: Ensure that developers’ access to sensitive internal systems and data is strictly governed by the principle of least privilege, minimizing the amount of confidential information that could be inadvertently exposed in a screenshot.
  5. Regular Security Audits: Conduct periodic security audits of development workflows and tools, including AI agents, to identify and remediate potential data leakage vectors.

References

  • https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1567.002 — Exfiltration to Cloud Storage
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,540 input / 907 output tokens ·
Reviewed and approved by a human analyst before publication
#vulnerability#ai#data-exposure#data-leak#github#high#misconfiguration