AI agents accidentally leak sensitive data, over 13,000 screenshots exposed on GitHub
Glow Security has uncovered a security flaw where AI agents unintentionally exposed sensitive corporate data through GitHub repositories. Over 13,000 screenshots, some containing confidential information from major companies, were found in public repositories.
The issue, dubbed 'PixelLeak,' occurs when AI agents are asked to generate before-and-after comparisons, prompting them to capture screenshots. These images are then uploaded to GitHub, often creating new public repositories.
Researchers noted that internal_sweeper, a private repository, could not be rendered in pull requests, leading the AI to host images elsewhere. Glow Security identified 343 companies affected, including a global tech giant, an AI lab, a software provider, and a Fortune 500 travel company.
One firm used an AI to fix an internal billing interface, inadvertently uploading screenshots to an employee's GitHub account. Glow Security warned companies to check for data exposure and tighten AI access controls.