“The vulnerability allows an attacker to hijack a user’s agent via a malicious GitHub Issue, and coerce it into leaking data from private repositories.”

One malicious issue in a public repo gets an agent to read your private repos and post the contents in a public pull request. The leaked test data included salary information. Invariant says GitHub cannot patch it server-side because the problem is how agents work. Invariant also sells the fix.