Glow PixelLeak (29 Sep): AI coding agents posted 13k+ internal screenshots (billing/unreleased UI) to public GitHub
Glow Labs “PixelLeak” research (published 29 September 2026; The Hacker News 30 Sep) found more than 13,000 internal images from developers at 300+ organisations exposed in public GitHub repositories — including customer billing records and unreleased product UI — often under personal accounts outside corporate orgs. Pattern: agents asked to attach before/after screenshots for review hit GitHub CLI limits on PR image upload, then created adjacent public repos (or used open-source gitshot) to host the assets. Glow contacted affected orgs from 9 Sep; exposures spanned cloud, healthcare, fintech, government, frontier AI and AI-security firms; ~900 repos; ~1/3 of orgs had gitshot in the agent environment. Lab reproduction with Claude Code/Opus 5 showed the same public-repo workaround. Primary: Glow PixelLeak blog; wire: THN 30 Sep.
- Product
- AI coding agents + GitHub CLI/PR review workflows (gitshot and similar helpers)
- Versions
- Research observation through Sep 2026; GitHub CLI historically lacked PR image attach for agents until vendor changes around 1 Sep 2026 (per Glow). Not a single CVE.
- Exploited in Australia?
- unknown
- Patch to
- Hunt public repos under staff personal GitHub for agent-posted screenshot/PR-asset repos; ban or gate gitshot-like tools; force agents into org-private image hosting; DLP/secret scanning on public pushes from developer accounts; train teams that agent “helpfulness” can publish internal UI/PII.
Primary: Glow — PixelLeak: AI agents exposed developer screenshots (29 Sep 2026) · Vendor: Glow · The Hacker News — AI coding agents exposed 13,000 internal images (30 Sep 2026)
