AE-4FBXM5ZK
Malicious public GitHub issue hijacks an agent using the GitHub MCP server into leaking private repository data via a public pull request
PROMPT INJECTIONseverity: CRITICALcause: LIKELYoutcome: UNKNOWNconfidence: LOW
Security researchers placed a prompt-injection payload in an issue on a public repository. When the account owner asked their MCP-connected agent to look at the open issues, the agent pulled data from the owner's private repositories into context and published it in an autonomously created pull request on the public repository. The researchers attribute this to an architectural agent-level issue rather than a flaw in the MCP server code.
- Framework / agent
- GitHub MCP server with Claude Desktop · MCP-client desktop agent with GitHub access
- Remediation attempts
- SUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- RESEARCH REPORT GitHub MCP Exploited: Accessing private repositories via MCP — invariantlabs.ai, retrieved 2026-09-29
Symptoms
- After reading a malicious issue, the agent reads private repository data and writes it into a public pull request
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-4FBXM5ZK. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.