Legit Security reports that hidden instructions in merge requests, comments or code could steer GitLab Duo, combined with unsanitized HTML in streamed responses, to leak private project code and confidential issues. GitLab was notified on 2025-02-12 and patched rendering of external-domain HTML tags.
Why it matters
Code assistants that read attacker-editable repository content can expose everything the victim user can access.
Key facts
As stated in the sources, with where to find them.
- GitLab notified 2025-02-12; the fix restricts rendering of HTML tags pointing to external domains.Disclosure section
- Concealment techniques included encoding, Unicode smuggling and white text rendering.Attack technique
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Oct 8, 2025
Jul 8, 2025
Jun 16, 2025
Jun 11, 2025
Jun 11, 2025
May 26, 2025