Organizations/security vendor

Legit Security

2 records2 attackWebsite
Oct 8, 2025
CamoLeak: hidden PR comments let GitHub Copilot Chat leak private code via image proxy
AttackVulnerability disclosureLegit Security, GitHub

Legit Security found that instructions in hidden pull request comments were processed by Copilot Chat for any user viewing the PR, and that GitHub's Camo image proxy could be used to encode private repository content into a sequence of image requests that bypassed the content security policy. Reported via HackerOne, GitHub fixed it on 2025-08-14 by disabling image rendering in Copilot Chat; Legit rates it CVSS 9.6.

May 22, 2025
Legit Security finds GitLab Duo prompt injection that could leak private source code
AttackVulnerability disclosureLegit Security, GitLab

Legit Security reports that hidden instructions in merge requests, comments or code could steer GitLab Duo, combined with unsanitized HTML in streamed responses, to leak private project code and confidential issues. GitLab was notified on 2025-02-12 and patched rendering of external-domain HTML tags.