{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/gitlab-duo-remote-prompt-injection-2025/",
 "asOf": "2026-09-26",
 "id": "gitlab-duo-remote-prompt-injection-2025",
 "date": "2025-05-22",
 "datePrecision": "day",
 "title": "Legit Security finds GitLab Duo prompt injection that could leak private source code",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Legit Security reports that hidden instructions in merge requests, comments or code could steer GitLab Duo, combined with unsanitized HTML in streamed responses, to leak private project code and confidential issues. GitLab was notified on 2025-02-12 and patched rendering of external-domain HTML tags.",
 "whyItMatters": "Code assistants that read attacker-editable repository content can expose everything the victim user can access.",
 "actors": [
  "legit-security",
  "gitlab"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo",
   "publisher": "Legit Security",
   "title": "Remote Prompt Injection in GitLab Duo Leads to Source Code Theft",
   "date": "2025-05-22",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "GitLab notified 2025-02-12; the fix restricts rendering of HTML tags pointing to external domains.",
   "locator": "Disclosure section"
  },
  {
   "fact": "Concealment techniques included encoding, Unicode smuggling and white text rendering.",
   "locator": "Attack technique"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}