Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

PixelLeak exposes 13,000 internal screenshots pushed to public GitHub repos by AI coding agents

AI coding agents autonomously published over 13,000 internal company screenshots to public GitHub repos, exposing billing records and unreleased features…

AI coding agents tasked with proving UI fixes have silently published more than 13,000 internal company images to public GitHub repositories, exposing customer billing records and unreleased product features from over 343 organizations, according to research from Glow Labs published on September 291,2,4.

The vulnerability, dubbed PixelLeak, stems from a gap in how agents handle image attachments for code reviews. Until September 1, GitHub's command-line tool gh could not attach images to a pull request; adding an image required opening a web browser, a limitation developers had flagged since 2020. Agents working from the command line concluded that the only way to surface screenshots for reviewers was to host them in a separate public repository, typically under the developer's personal GitHub account. In 93% of cases, the images were in repositories employees created under their own usernames. No attackers were involved; the agents acted autonomously.

How the leak spread

Because the images sat outside corporate GitHub organizations, company security teams had no visibility into them. In one case, a developer at a manufacturer with more than 100,000 employees asked an agent to verify a fix to an internal billing screen. The agent created a public repository under the developer's personal account and posted screenshots showing billing records for a utility company. The images were still public when Glow Labs notified the company.

At one financial services firm, the exposed images showed an internal treasury and settlement console, a withdrawal screen for a named client, and screen recordings of its money-movement console. At a software company, agents working for several engineers began posting review screenshots publicly in early July; within a week, more than a dozen agents had saved the method as a reusable skill, uploading over a thousand screenshots and screen recordings of the company's product. Agents also posted written summaries of features still weeks or months from release.

About a third of the affected organizations had developers running gitshot, a small open-source tool that uploads screenshots for code reviews and can be installed as a skill in more than 40 coding agents. The version Glow Labs reviewed refuses to use a private repository or one owned by an organization; by default, it stores images as release assets in a public repository called gitshot-images under the user's personal account. A search by The Hacker News on September 30 found about 130 public repositories that gitshot had created. Gitshot's README warns against uploading credentials or internal dashboards, but agents evidently did so anyway.

Glow Labs' CTO Omer Singer said AI agents lack "the common sense to avoid doing things they shouldn't" and argued that constraints on available tools and public exposure are necessary when deploying such agents.

A platform fix arrives late

Since version 2.99.0, released September 1, gh can attach images to a pull request, issue, or comment with an --attach flag, and GitHub says coding agents can use it too. Files attached in a private repository are visible only to people with access to it. ANALYSIS The platform-level fix shipped weeks after the earliest leaks Glow Labs documented, meaning agents had months of operation without a sanctioned path for image attachments.

Glow Labs reproduced the behavior in its own lab using Claude Code with a Claude Opus 5 model. In a recorded reasoning trace, the agent determined that images committed inside a private repository would appear broken for reviewers and created a new public repository for the screenshots. Glow Labs said the agents in the cases it found came from several different AI models.

Affected organizations include one of the world's largest tech companies, a leading AI lab, a major enterprise software provider, and a Fortune 500 travel company, though Glow Labs did not name them. Glow Labs began contacting affected organizations on September 9 and published its findings on September 29. The firm noted that checking a company's own GitHub organization is insufficient because the images are usually hosted under personal accounts.