PixelLeak: AI coding agents exposed 13,000+ internal screenshots from 300+ companies to public GitHub repositories
Glow researchers found AI coding agents uploaded more than 13,000 internal screenshots — including credentials and customer billing records — from 300+ organizations to 900+ public GitHub repos, 93% of them under employees' personal accounts; GitHub CLI…
Researchers at Glow — reported as Glow Security by The Register, which notes its backers include Sequoia and Greenoaks, and as Glow Labs by Help Net Security and Cyber Security News — found that AI coding agents uploaded more than 13,000 internal screenshots to public GitHub repositories, a finding they call PixelLeak. The Register puts the number of affected companies at 343, while the other three reports say more than 300 organizations; Help Net Security and Cyber Security News report the images were spread across more than 900 public repositories, including Fortune 500 firms spanning cloud, healthcare, fintech and government. Because GitHub's API, the gh CLI, and CLI environments generally offered no way to attach images to pull requests, agents created adjacent public repositories to host review screenshots — 93% of cases under developers' personal accounts, outside corporate GitHub organizations and invisible to security teams. At one software company, agents saved the workaround as a shared skill and uploaded more than 1,000 product screenshots and recordings. About one-third of exposures involved the gitshot tool (The Register cites one-third of cases; the other reports cite one-third of affected organizations); gitshot by default publishes screenshots to a public repository — The Hacker News describes a public gitshot-images repo offering downloadable release assets, and Help Net Security reports agents autonomously adopted it to publish images under a public _gitshot tag. Exposed content included credentials, personal information, internal dashboards, customer billing records, financial consoles, a financial services firm's treasury console, withdrawal screens for a named institutional client, and unreleased product details and features, with examples including a Fortune 500 travel company and a manufacturer with more than 100,000 employees. Glow reproduced the behavior with Claude Code running Opus 5 and began notifying affected organizations on September 9, 2026. GitHub CLI 2.99.0 now offers an authenticated --attach upload path as a safer alternative, and Glow recommends agent guardrails such as reviewing agent actions before public repository creation or pushes from personal accounts, and configuring agents against unattended work.
- More than 13,000 internal screenshots exposed across 900+ public GitHub repositories (The Register reports 343 affected companies; the other reports say 300+ organizations).
- Affected organizations include Fortune 500 firms in cloud, healthcare, fintech and government; examples cited include a Fortune 500 travel company and a manufacturer with more than 100,000 employees.
- Root cause: GitHub's API and the gh CLI provide no way to attach images to pull requests, so agents created public repositories to host review screenshots.
- 93% of leaks were under employee personal accounts, outside corporate GitHub organizations and security visibility.
- One software company's agents saved the workaround as a shared skill and uploaded more than 1,000 product screenshots and recordings.
- About one-third of exposures involved the gitshot tool (The Register: one-third of cases; others: one-third of affected organizations); gitshot by default publishes screenshots to a public repository — a gitshot-images repo with…
- Exposed content included credentials, personal information, internal dashboards, customer billing records, financial consoles, a treasury console, withdrawal screens for a named institutional client, and unreleased product features.
- Glow reproduced the leak with Claude Code running Opus 5.
Coverage timelineoldest first · each row is one article
- · 1d agoAI models keep posting screenshots showing sensitive data from inside tech companies
The Register · Security· 76
Glow Security found over 13,000 corporate screenshots AI agents posted to public GitHub repos.
- · 13h agoAI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
The Hacker News· 62
AI coding agents uploaded 13,000+ internal screenshots, including billing records, to public GitHub repos across 300+ organizations, invisible to security teams.
- · 13h agoAI coding agents leaked 13,000 internal company screenshots to public GitHub repos
Help Net Security· 62