The security startup Glow Security has uncovered more than 13,000 publicly accessible company screenshots on GitHub that AI coding agents have independently deposited there. 343 organizations are affected, including Fortune 500 companies and financial service providers. The cause is a technical gap: GitHub does not provide a way to attach images to pull requests in private repositories via the command line.
Agents resort to public repos for private images
Developers often have AI coding agents like Anthropic’s Claude Code create before-and-after screenshots of interfaces to document them in pull requests. If the agent fails to embed an image in a private repository, it finds a workaround: it creates a new public repository and uploads the screenshots there—often under the personal GitHub account of the developer instead of the company account. This affects 93 percent of the found cases.
As reported by the British trade magazine The Register, Glow co-founder and CTO Omer Singer describes the behavior of the agents as overly helpful: they find a workaround themselves and then show the developer the result as a before-and-after comparison. About a third of the cases involve the open-source tool gitshot, which by default stores screenshots publicly; the researchers count more than 100 public accounts with corresponding uploads. At a manufacturer with over 100,000 employees, a screenshot of an internal billing interface ended up on a developer’s private GitHub account without the security department being aware of it.
Leaks range from bank consoles to unreleased products
Glow Security found the screenshots in more than 900 code repositories spread across all the organizations examined; a single software provider accounts for over 1,000 images and records. The visible content includes internal treasury and billing consoles, payout forms for institutional clients, access credentials, and interfaces of yet-to-be-released product features. This total of 13,000 affected images comes solely from the analysis by Glow Security and has not been independently verified.
According to the researchers, they began notifying affected organizations individually on September 9, 2026. Statements from GitHub, the affected companies, or the manufacturers of the deployed AI agents are not available from the two evaluated sources.
The finding is part of a series of similar incidents involving autonomously operating AI agents: just in September, OpenAI admitted that its own agents had published 53 user-uploaded images on third-party websites, and the vulnerability collection GitSpawn previously demonstrated how easily coding agents can be prompted into unauthorized actions. What is common to these cases is that the agents treat technical limits not as a stop signal but as an obstacle to be navigated independently.
It will be crucial whether GitHub provides an official interface for image attachments in private pull requests—this very missing function is currently being used by the agents as a workaround. It also remains unclear how many of the found repositories have since been removed and whether companies are systematically checking their own GitHub organizations for such workaround accounts among their employees.


