AE Agent Errors
AE-4FBXM5ZK

Malicious public GitHub issue hijacks an agent using the GitHub MCP server into leaking private repository data via a public pull request

PROMPT INJECTIONseverity: CRITICALcause: LIKELYoutcome: UNKNOWNconfidence: LOW

Security researchers placed a prompt-injection payload in an issue on a public repository. When the account owner asked their MCP-connected agent to look at the open issues, the agent pulled data from the owner's private repositories into context and published it in an autonomously created pull request on the public repository. The researchers attribute this to an architectural agent-level issue rather than a flaw in the MCP server code.

Framework / agent
GitHub MCP server with Claude Desktop · MCP-client desktop agent with GitHub access
Remediation attempts
SUGGESTED
Recurrence
not documented
Source languages
en
Updated
2026-09-30

Sources

Symptoms

  • After reading a malicious issue, the agent reads private repository data and writes it into a public pull request
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-4FBXM5ZK. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.