VulnWatch VulnWatch
← Back to dashboard
Unknown rss_bleepingcomputer · rss_23c14337daef23d0d5f994a044abdddd

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

Published Jul 11, 2026

A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. [...]

Affected AI Products

prompt injection ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.