Registry/APM-0011
Case No.
APM-0011
Filed
April 13, 2026
Severity
5 / 5 — CRITICAL

LangChain agent published internal pricing spreadsheet to public S3 bucket

Attribution Anonymous
Prompt

Move the Q3 pricing docs over to S3 so the sales team can easily access them

A LangChain-based document processing agent was given access to both an internal SharePoint and an AWS S3 bucket used for public assets. A business analyst asked it to 'move the Q3 pricing docs to S3 so the sales team can access them easily'. The agent moved all documents with 'pricing' in the filename — including a master pricing strategy document and competitor analysis — to the public-facing S3 bucket with public-read ACL. The files were indexed by Google within 6 hours. A competitor found them via search.