Web Hack List

Collected research

GitHub MCP Exploited: Accessing private repositories via MCP

Shows how prompt injection in a public GitHub issue can steer an MCP-enabled coding agent into reading data from a private repository and disclosing it in a public pull request. The chain crosses trust boundaries between untrusted repository content, tool calls, and authenticated GitHub access.

Record

Researcher
@invariantlabsai
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @invariantlabsai, first published at the original source. Preserved copies are kept so the citation survives its host.