AI Agents Leaked More Than 13,000 Screenshots Into Public GitHub Repositories, Researchers Find
Security researchers have documented more than 13,000 screenshots left in public GitHub repositories by AI agents, in a leak pattern they call “PixelLeak” that has exposed sensitive information from 343 companies.
September 30 (IT Home) — According to a report today by the technology outlet TechRadar, the cybersecurity research firm Glow Security recently found more than 13,000 screenshots in public GitHub repositories created by AI agents, some of which contained sensitive information belonging to various technology companies.
IT Home learned from the original report that this kind of leak is called “PixelLeak.” The researchers explain that people sometimes ask an AI agent for before-and-after images of a project change, which requires the agent to take a screenshot. GitHub does provide an image hosting service, so an agent may unknowingly upload the screenshot to a public repository.
One of the researchers said: “For example, internal_sweeper is a private repository, and GitHub cannot render private-repository images inside a pull request. So the agent had no choice but to host the PNG images somewhere else, which created the public repository sweeper-demo / pr-assets and pinned the two screenshots to a commit SHA.”
The firm also found that 343 companies have leaked sensitive information in this way, including one of the world’s largest technology companies, a frontier AI laboratory, a large enterprise software vendor and a Fortune 500 travel company.
One of these companies was using an agent to fix an internal billing interface. To complete the task a human had assigned, the AI uploaded the screenshot to a code repository on an employee’s personal GitHub account in order to show the result of the changes.
Glow Security says that when it notified this company about the leak, the exposed screenshots were still public. It advises companies to check their own data exposure immediately and to tighten controls over AI permissions.

评论
0 条讨论
登录后发表评论
立即登录暂无评论
成为第一个分享想法的人吧!