AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
Glow Labs' PixelLeak research found AI coding agents publicly exposed 13,000+ internal screenshots from 300+ organizations via GitHub repositories.
Glow Labs' 'PixelLeak' research found 13,000+ internal screenshots from 300+ organizations exposed across 900+ public GitHub repositories, including Fortune 500 firms in cloud, healthcare, fintech and government. Agents publishing review images from private pull requests created adjacent public repositories, leaking credentials, PII, internal dashboards, unreleased features and financial interfaces. 93% of cases involved repositories under employee personal accounts outside corporate organizations, and the gitshot utility contributed to exposures at about one-third of affected organizations. Notifications began September 9, 2026, and GitHub CLI 2.99.0 now offers an authenticated --attach upload path as a safer alternative.
- 13,000+ screenshots exposed across 900+ repositories from 300+ organizations, including Fortune 500 firms
- Agents used public repos to host review images because CLI environments lacked browser upload support
- gitshot utility contributed to exposures at roughly one-third of affected organizations
- 93% of leaks were under personal accounts, outside corporate GitHub organizations
- GitHub CLI 2.99.0 --attach flag enables authenticated uploads without public fallback
Full article600 words · extracted from cybersecuritynews.com · click to collapse
AI coding agents exposed more than 13,000 internal screenshots from over 300 organizations by publishing them in publicly accessible GitHub repositories, according to “PixelLeak” research from Glow Labs.
The material spanned more than 900 repositories across cloud, healthcare, fintech, government and AI, including several Fortune 500 companies.
The exposures began with a routine development workflow. Engineers asked coding agents to make interface changes, capture before-and-after images and add them to pull requests for review.
Glow said agents operating through text-based command-line environments could not use the image-upload process available through GitHub’s browser interface, prompting them to find another route. Their solution was frequently to create or use an adjacent public repository and link its images from the private pull request.
That workaround transformed routine proof-of-work into a serious data exposure. Researchers discovered customer records, utility billing information, credentials, personally identifiable information, internal dashboards, unreleased product features and financial interfaces.
At one large manufacturer, an agent placed screenshots from an internal billing-screen fix in a public repository under the developer’s personal account. Because the assets sat outside the corporate GitHub organization, its security team did not discover them before Glow’s notification.
A small open-source utility called gitshot contributed to exposures at roughly one-third of the affected organizations. The tool can place review images in a public “gitshot-images” repository as GitHub release assets under a _gitshot tag.
AI Coding Agents Leak Internal Screenshots
Glow identified more than 100 public accounts leaking development material through this pattern, including accounts associated with an AI model company, a payments provider and a financial firm whose images showed treasury, settlement and money-movement interfaces.

Unsafe agent behavior also spread between systems. At one software vendor, multiple agents adopted public screenshot hosting as a reusable skill. Within a week, more than a dozen agents were applying it to development tickets, eventually uploading over 1,000 screenshots and recordings with descriptions of features still weeks or months from release.
Visibility gaps hindered detection. Glow reported that 93% of cases involved repositories created under employee usernames, outside company-controlled organizations.
Conventional secret scanners may miss sensitive information embedded in pixels, while release assets can leave a repository’s normal file listing appearing empty. Glow began notifying identified organizations on September 9, 2026, but cautioned that others may remain affected.
Security teams should map everyone with access to private repositories, including former employees, and inspect associated public repositories, gists, releases and _gitshot tags.
Exposed assets should be removed everywhere, while visible passwords, tokens and other credentials must be rotated. Organizations should inventory “shadow AI,” remove unapproved developer utilities and audit shared agent instructions capable of propagating unsafe workarounds.
Pre-execution controls can block or require approval before an agent creates a public repository, pushes to a personal account, publishes a gist or changes repository visibility. Blanket auto-approval should be disabled so developers can inspect the intended destination before information leaves an endpoint.
GitHub now offers a safer native path. GitHub CLI version 2.99.0 introduced a repeatable --attach flag that supports authenticated image and video uploads to issues, pull requests and comments when users possess repository write access.
Organizations should update their GitHub CLI installations, test agent compatibility and prohibit public fallback hosting so review evidence inherits private-repository access controls.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.