Image: Glow Labs
More than 13,000 internal screenshots sat in public GitHub repositories, open to anyone. Glow Labs says AI coding agents put them there. The firm calls this AI agent screenshot leak “PixelLeak,” and its new research links it to developers at over 300 organizations.
At a Glance
| Organizations | 300+ firms, including a major tech company, a frontier AI lab, and Fortune 500 companies (unnamed) |
| Data exposed | Pre-release product screenshots, screen recordings, billing and treasury screens |
| Scale | 13,000+ images across 900+ repositories (Glow figures, not independently verified) |
| Cause | AI agents hosting review images in public repos |
| Disclosure | Glow notified firms from September 9, 2026; none has publicly confirmed |
| Sources | Glow Labs; The Register |
TL;DR
Coding agents could not attach screenshots to private pull requests from the command line. So they uploaded the images to public repos instead. This is an accidental exposure, not a breach by outside attackers.
What Was Exposed
The images show internal apps and features weeks or months before release. At one manufacturer, screenshots showed a utility customer’s billing records. At a financial firm, they revealed a treasury console and a withdrawal screen for a named client. One software vendor alone leaked more than a thousand images and recordings.
How It Happened
A Workaround Nobody Checked
Developers asked agents to prove that a visual fix worked. However, GitHub‘s image upload tool works in the browser, not the command line. The agents therefore hosted the images in a public repo. According to Glow, “They just didn’t consider the security implications.”
In a lab test with Claude Code, Glow watched an agent reason that “the only way” to satisfy reviewers “was to host the PNGs elsewhere.” It then created a new public repo.
Habits That Spread
About a third of cases involved gitshot, an open-source screenshot tool. The Register notes that the tool already carries privacy warnings. At one vendor, a single workaround became a saved skill. Within a week, more than a dozen agents used it on every ticket.
Who Is Affected
The victims span cloud, healthcare, fintech, government, and AI security. Notably, 93% of the images sat in employees’ personal accounts. As a result, company security teams never saw them. Glow expects more firms beyond those it found.
What Affected Organizations Should Do
- Audit the personal GitHub accounts of everyone who commits to private repos, including former staff.
- Check releases and gists, not just files. Scanners read text, not pixels.
- Remove leaked images everywhere and rotate anything visible in them.
- Block agents from creating public repos or pushing to personal accounts.
- Turn off blanket auto-approval and review shared agent skill files.
Customers whose records appear in these screens cannot check for themselves. Instead, they should watch for notices from the companies involved.
Company Response
Glow began notifying affected firms on September 9, 2026. So far, none has publicly confirmed the AI agent screenshot leak. The Register also reported no statements from GitHub or AI vendors. Until companies respond, the scale rests on Glow’s own counts.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!