GLOW Labs has exposed more than 13,000 internal screenshots by fault of AI coding agents that uploaded images to public GitHub repositories. The firm flags this as PixelLeak, linking the leak to developers at over 300 organisations. The exposed data spans pre-release screenshots, screen recordings, and sensitive billing and treasury interfaces. The scope is said to be 13,000+ images across 900+ repositories, according to Glow, though this scale is not independently verified. The disclosure began on 9 September 2026, with no firm having publicly confirmed the incident as of the article’s publication.
The leak occurred when developers asked AI agents to prove a visual fix worked; the agents chose to host screenshots in public repos because GitHub’s image upload tool operates in the browser, not via the command line. Glow cites lab testing with Claude Code in which an agent concluded that hosting PNGs elsewhere was the only way to satisfy reviewers, leading to the creation of new public repos. About a third of cases involved gitshot, an open-source screenshot tool that already carries privacy warnings.
Affected organisations span cloud, healthcare, fintech, government and AI security sectors, with 93% of images sitting in employees’ personal accounts, meaning security teams did not see them. Recommendations include auditing personal GitHub accounts, inspecting releases and gists, removing leaked images, blocking agents from public repos, and tightening review of agent skills files. Glow has begun notifying firms, but no formal statements from GitHub or AI vendors have been reported.