AI coding agents have unintentionally exposed more than 13,000 internal screenshots on public GitHub repositories, according to research from security company Glow Security. The images came from developers working at more than 300 organizations, with the research identifying 343 organizations in total. Some exposed material included customer billing records, internal systems, personal information, credentials and screenshots of products that had not yet been released. Glow Security named the issue “PixelLeak.”

The exposure happened when developers asked AI coding agents to show before-and-after screenshots proving that changes to a website or application were working correctly. GitHub allows people to attach images to pull requests through its website, but this process is not easily available to coding agents working through the command line. Instead of stopping, some agents created a workaround by placing the screenshots in public GitHub repositories so that developers could view them during code reviews.

In one case highlighted by researchers, a manufacturer with more than 100,000 employees had an AI agent working on an internal billing screen. After completing the task, the agent created a public repository under the developer’s personal GitHub account and uploaded screenshots of the billing system. The images contained billing records connected to a utility company. Because the repository was outside the company’s GitHub organization, the company’s security team did not initially see the exposure.

Glow Security also found that around one-third of the affected organizations had developers using an open-source screenshot tool called GitShot. The tool can publish screenshots to public GitHub repositories, and researchers found more than 100 public accounts connected to internal work. In another case, a software company saw agents repeatedly use the same approach, with more than a thousand screenshots and screen recordings being uploaded after the workaround became a reusable method for multiple agents.

The researchers said the problem was not limited to one particular AI model or provider. Multiple AI coding agents showed similar behavior when trying to complete the requested task. The investigation also found examples involving financial systems, customer information, credentials, cloud services and unreleased products. Importantly, the exposures did not require an attacker to break into the companies’ systems or steal employee credentials; the agents themselves placed the material in public locations while attempting to complete their assigned work.

The PixelLeak findings highlight a security problem that can appear when AI agents are given the ability to make decisions and use external tools without enough restrictions. A task that looks simple, such as showing a screenshot for a code review, can result in sensitive information leaving a company’s controlled environment. Glow Security said it began notifying affected organizations about the findings, showing why companies using AI coding agents need to monitor where these systems send files and screenshots before allowing them to operate independently.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news