2 min read

PixelLeak exposes 13,000 internal screenshots on GitHub

Vlad CONSTANTINESCU

October 01, 2026

PixelLeak exposes 13,000 internal screenshots on GitHub

AI coding agents published internal screenshots from over 300 organizations, exposing billing records and unreleased features.

Key takeaways

  • Glow Labs found over 13,000 internal images exposed on public GitHub repositories
  • The screenshots included customer billing information and unreleased product features
  • GitHub now supports command-line attachments, but previously published material still needs attention

How private screenshots became public

AI coding assistants turned routine software checks into public data exposure, according to Glow Labs. Its Sept. 29 PixelLeak report describes internal screenshots appearing across more than 900 repositories linked to over 300 organizations. Developers had asked agents to demonstrate visual changes before submitting work for review.

When agents encountered difficulties attaching screenshots, they uploaded them to separate public repositories. Glow says 93% of the cases involved repositories under the employees’ own usernames, making the exposure harder for company security teams to detect. One incident revealed utility billing records. The findings establish public exposure; they do not establish that criminals downloaded or exploited the images.

GitHub has addressed the attachment gap

The workaround addressed a real limitation that has since changed. On Sept. 1, GitHub introduced image and video attachments in version 2.99.0 of its command-line tool, allowing agents to attach files directly to pull requests, where developers review proposed changes. That release does not support GitHub Enterprise Server.

Updating the tool does not remove earlier uploads. Teams should also review reusable agent instructions: Glow found that one software vendor’s agents had saved the public-upload workaround as a skill, then repeatedly used it. The practical lesson is to check where an agent stores evidence, alongside checking whether its code works.

Keep track of your exposed information

For anyone using coding agents, review screenshot destinations before approving uploads and remove personal details from test data. If an image exposes a password or access token, revoke or replace it. Customer information visible in screenshots could also make impersonation attempts more convincing, so verify unexpected account messages through the provider’s official app or website.

For ongoing awareness of personal data exposure, Bitdefender Digital Identity Protection monitors both the public and dark web, alerts you to detected breaches involving your details, and provides guidance on securing affected accounts.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader