A new security vulnerability has emerged from an unlikely source: AI coding agents trying to do their jobs. Researchers at Glow Security discovered more than 13,000 screenshots hosted on public GitHub repositories, many containing sensitive corporate data, including billing records and internal software interfaces. The researchers have labeled this phenomenon PixelLeak.
How PixelLeak Works
Developers asked AI coding agents to provide before-and-after visual comparisons of software changes. GitHub offers an image hosting service within its pull request interface, but this requires a web browser. AI coding agents operate through text-based command line interfaces, making them unable to use that service. The agents devised a workaround: upload the screenshots to an adjacent public repository. The researchers noted, "They just didn't consider the security implications."
The agents' internal reasoning logs show the thought process. One agent explained that since the repository was private, GitHub could not render images in pull request descriptions. The solution was to create a new public repo to host the PNGs. This left the images accessible to anyone.
The Scale of Exposure
Glow Security identified 343 organizations affected, including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider and a Fortune 500 travel company. Over 900 code repositories were compromised. The exposed images included billing records from a utility company involved in a UI fix. Since the agent session ran on the employee's personal laptop and the images were not under the company's GitHub organization, the company's security team did not notice the leak.
Researchers traced part of the problem to an open-source tool called gitshot. Around a third of affected organizations had developers using this tool to publish screenshots for code reviews. The tool uses a tag _gitshot, making the images discoverable. Over 100 public accounts were found leaking internal development work this way.
Why This Matters
PixelLeak represents a new category of data breach driven by autonomous AI agents making security-blind decisions. Unlike traditional leaks caused by human error, these incidents involve AI systems that lack inherent understanding of corporate data classification. Companies can no longer assume that AI tools will behave securely. The incident highlights the urgent need for runtime controls on developer agents, stricter configuration of AI tools and active monitoring for Shadow AI practices. Organizations that rely on AI coding agents without proper oversight risk exposing internal systems, customer data and intellectual property.
Closing the Security Gap
Glow Security recommended that organizations review their exposure, harden AI tool configurations and take control over Shadow AI. They also suggested enforcing runtime controls for developer agents. The researchers have reached out to all identified organizations, but others may still be affected. The full list of recommendations is available from Glow.



