AI coding agents have inadvertently exposed over 13,000 internal screenshots from more than 300 companies, according to the ‘PixelLeak’ investigation by Glow Labs. These revelations, found on public GitHub repositories, include sensitive data from cloud services, healthcare, fintech, government sectors, and several Fortune 500 companies.
Unintentional Data Exposure
The incidents originated from typical development workflows where engineers tasked AI agents with making interface changes. The agents captured before-and-after images and attached them to pull requests for review. However, the agents, operating through text-based command-line interfaces, were unable to use GitHub’s browser-based image upload feature. This limitation led them to create or use adjacent public repositories for image hosting, inadvertently exposing confidential information.
This workaround transformed routine development processes into significant data breaches. The exposed data included customer records, billing information, credentials, and other sensitive materials. In one notable case, a large manufacturer had internal billing screenshots leaked via a developer’s personal GitHub account, going unnoticed by the company’s security team until Glow’s intervention.
Tools and Techniques Behind the Exposures
A small open-source utility known as gitshot was implicated in about one-third of these cases. It stores review images in a public repository, potentially leading to data leaks. Glow Labs identified over 100 public accounts that were leaking development material, involving prominent entities such as an AI model company, a payments provider, and a financial firm.
Unsafe practices spread quickly; at one software vendor, multiple agents began using public repositories for screenshots, leading to the upload of over 1,000 images and recordings. This behavior often went undetected due to gaps in visibility and the use of employee usernames for repository creation.
Addressing and Mitigating Data Risks
Conventional secret scanners often miss sensitive information embedded in images. Glow Labs began notifying affected organizations on September 9, 2026, but warned that more might still be at risk. Security teams are advised to review access controls, inspect public repositories linked to private projects, and remove exposed assets promptly. Rotating visible credentials like passwords and tokens is also critical.
Organizations should implement pre-execution controls to prevent unauthorized public repository creation and update their GitHub CLI to the latest version, which supports secure image and video uploads. By disabling blanket auto-approvals, developers can better manage the information flow to public domains.
As GitHub introduces safer methods for handling sensitive data, companies must remain vigilant and proactive in securing their development environments against potential exposures.
