Organizations/platform

GitLab

1 records1 attackWebsite
May 22, 2025
Legit Security finds GitLab Duo prompt injection that could leak private source code
AttackVulnerability disclosureLegit Security, GitLab

Legit Security reports that hidden instructions in merge requests, comments or code could steer GitLab Duo, combined with unsanitized HTML in streamed responses, to leak private project code and confidential issues. GitLab was notified on 2025-02-12 and patched rendering of external-domain HTML tags.