AI News Feed
Market watch
Cybersecurity

AI Coding Agents Leaked 13,000 Screenshots in 'PixelLeak' GitHub Exposure

Glow Security says AI coding agents leaked over 13,000 screenshots, some sensitive, to public GitHub repos in 'PixelLeak'.

Glow Security said each case began when a developer asked an AI agent to prove that a visual change worked. A software update, such as a fix to a user interface layout, required reviewers to see before-and-after images. GitHub offers an official image hosting service inside its pull request interface for human developers using a web browser, but the agents operated through a text-based command line interface and could not include the screenshots for review through that method.

The agents created workarounds by hosting images in adjacent public repositories so human reviewers could see them, according to the researchers. The agents did not consider the security implications. Glow Security traced the problem in logs containing the agents' reasoning. One agent explained that GitHub could not render images from a private repository in a pull request description because its image proxy fetches anonymously, so the agent created a new public repository to hold the screenshots pinned to a commit SHA.

Glow Security said it identified 343 organizations leaking sensitive information this way, including one of the world's largest technology companies, a frontier AI laboratory, a major enterprise software provider, and a Fortune 500 travel company. More than 900 code repositories were affected, according to the researchers. One manufacturer employing more than 100,000 people was verifying a fix to an internal billing screen. The agent uploaded screenshots to a public repository in the developer's personal GitHub account.

The exposed images included billing records for a utility company involved in the user interface fix, Glow Security said. Because the agent session ran on the employee's laptop and the public images were not on the company's GitHub organization, the company's security team did not identify the issue, and the images were still online when Glow Security notified the company.

The researchers also traced the problem to gitshot, a small open-source tool that publishes screenshots for code reviews. About a third of affected organizations had developers using the tool, Glow Security said. Agents working for developers at several large organizations used gitshot to work around the GitHub command line attachment limitation, publishing images with a _gitshot tag that anyone could find if they knew where to look. More than 100 public accounts were found leaking internal development work this way.

Glow Security said it reached out to all the organizations it could identify but stressed that others might be affected. Its recommendations included reviewing exposure, hardening AI tool configurations, taking control over Shadow AI, and enforcing runtime controls for developer agents. TechRadar reported that the full list of recommendations is available online.