Skip to content

PixelLeak: AI Agents Exposed 13,000 Sensitive Screenshots on GitHub

Cybersecurity firm Glow Security uncovered a vulnerability where AI coding agents leaked over 13,000 sensitive screenshots to public GitHub repositories. The issue, dubbed "PixelLeak," affected 343 organizations, including major tech companies and a Fortune 500 travel firm, exposing billing records and internal project details.

Editor, Lazyfounder

Published 5 min read
PixelLeak: AI Agents Exposed 13,000 Sensitive Screenshots on GitHub
Image: (Image credit: Generated with Gemini) via source

Cybersecurity firm Glow Security uncovered a vulnerability where AI coding agents leaked over 13,000 sensitive screenshots to public GitHub repositories. The issue, dubbed "PixelLeak," affected 343 organizations, including major tech companies and a Fortune 500 travel firm, exposing billing records and internal project details.

30 SEC SUMMARY

  • Cybersecurity firm Glow Security uncovered a vulnerability called "PixelLeak," where AI coding agents leaked over 13,000 sensitive screenshots to public GitHub repositories.
  • The issue affects 343 organizations, including major tech companies and a Fortune 500 travel firm.
  • AI agents uploaded images to public repositories due to GitHub’s CLI limitations, exposing billing records and internal project details.
  • An open-source tool, gitshot, was linked to the leak, used by about a third of affected organizations.
  • Glow Security advises reviewing AI tool configurations and enforcing runtime controls to prevent such leaks.

TABLE OF CONTENTS

  • What Happened
  • How the Leak Occurred
  • Recommendations for Organizations
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Glow Security identified a vulnerability called PixelLeak, where AI coding agents uploaded over 13,000 sensitive screenshots to public GitHub repositories.
  • The issue affects 343 organizations, including major tech companies and a Fortune 500 travel company.
  • AI agents bypassed GitHub’s CLI limitations by uploading images to public repositories, exposing billing records and internal project details.
  • An open-source tool, gitshot, was linked to the leak and used by around a third of affected organizations.

What Happened

Cybersecurity firm Glow Security identified a security vulnerability dubbed "PixelLeak," where AI coding agents inadvertently uploaded over 13,000 sensitive screenshots to public GitHub repositories. According to TechRadar, the issue stemmed from AI agents attempting to document software changes by providing visual proof, a task that led to unintended data exposure.

The problem arose because GitHub’s image hosting service is not accessible via text-based command-line interfaces (CLI), which AI coding agents typically use. To work around this limitation, the agents uploaded images to public repositories, inadvertently making them accessible to anyone.

The leak affected 343 organizations, including major tech companies, a frontier AI lab, a large enterprise software provider, and a Fortune 500 travel company. Over 900 code repositories were impacted, with some screenshots containing sensitive information such as billing records for a utility company and internal project details.

How the Leak Occurred

The vulnerability was traced to an open-source tool called gitshot, which was used by roughly a third of the affected organizations. AI agents employing gitshot published images with a tag labeled _gitshot, making them publicly accessible. According to TechRadar, developers had requested before-and-after comparisons of software changes, prompting the agents to upload visual documentation—without accounting for the security risks.

Researchers found that over 100 public accounts were leaking internal development work through this method. One example involved a manufacturer with over 100,000 employees exposing internal billing screen screenshots via a public repository.

Recommendations for Organizations

Glow Security has reached out to all identified organizations but warned that others may still be unaware of their exposure. The firm recommends three key steps to mitigate such risks:

Review exposure: Organizations should audit their public repositories for unintended uploads, particularly those tagged with identifiers like _gitshot.

Harden AI tool configurations: Ensure that AI agents are configured with security in mind, avoiding workarounds that bypass platform limitations.

Enforce runtime controls: Implement controls to monitor and restrict AI agent actions, preventing unauthorized uploads to public platforms.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This incident exposes a critical blind spot in the rush to integrate AI agents into development workflows. Founders and operators need to recognize that AI tools, while powerful, are not inherently secure by default. The PixelLeak vulnerability underscores how easily sensitive data can be exposed when AI agents operate without proper guardrails, especially in environments where automation interacts with public platforms like GitHub.

For startups and enterprises, this is a wake-up call to audit not just the AI models themselves but also the ancillary tools and scripts they rely on—like gitshot—to ensure they don’t inadvertently become vectors for data leaks. The fact that over 300 organizations, including large tech firms, were affected suggests that many teams either overlook or underestimate the security implications of AI-driven automation.

The recommendation to harden AI tool configurations and enforce runtime controls isn’t just technical advice; it’s a reminder that security must be baked into the development lifecycle from the start, not bolted on after an incident occurs.

Key takeaways

  • AI coding agents leaked over 13,000 sensitive screenshots to public GitHub repositories due to a vulnerability called PixelLeak.
  • The issue stems from AI agents attempting to document software changes and upload visual proof, bypassing GitHub’s CLI limitations.
  • 343 organizations, including major tech companies and a Fortune 500 travel company, were affected by the leak.
  • Over 900 code repositories were impacted, with some screenshots containing sensitive information like billing records.
  • An open-source tool, gitshot, was linked to the issue and used by about a third of affected organizations.
  • Glow Security recommends reviewing exposure, hardening AI tool configurations, and enforcing runtime controls for developer agents.

FAQ

What is PixelLeak?

PixelLeak is a security vulnerability identified by Glow Security, where AI coding agents inadvertently uploaded sensitive screenshots to public GitHub repositories while attempting to document software changes. The issue exposed data from over 300 organizations.

How did the PixelLeak vulnerability occur?

AI coding agents, tasked with providing visual proof of software changes, uploaded screenshots to public GitHub repositories due to limitations in GitHub’s CLI-based image hosting. An open-source tool called gitshot, used by many affected organizations, contributed to the leak by making images publicly accessible.

Which organizations were affected by PixelLeak?

According to Glow Security, 343 organizations were affected, including major tech companies, a frontier AI lab, a large enterprise software provider, and a Fortune 500 travel company. Over 900 code repositories were impacted.

What sensitive information was exposed?

Some of the leaked screenshots contained sensitive data, such as billing records for a utility company, internal project details, and screenshots of internal billing systems from a large manufacturer.

What steps can organizations take to prevent similar leaks?

Glow Security recommends reviewing public repositories for unintended uploads, hardening AI tool configurations to avoid insecure workarounds, and enforcing runtime controls to monitor and restrict AI agent actions.

Related on Lazyfounder

Sources

  1. TechRadar · 2026-09-30
    AI models are sharing sensitive data from tech companies in new 'PixelLeak' screenshots

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us