STUPID-2026-0061
A hidden comment made GitLab Duo leak private source code and inject rogue HTML
Instruction given
Use GitLab Duo Chat to help with code in a project.
Expected behavior
Ignore instructions hidden in comments, commits, or merge-request text; never leak private source or render attacker HTML.
Actual behavior
GitLab Duo parsed malicious prompts hidden in comments, source code, merge-request descriptions, and commit messages (via Unicode smuggling, base16 payloads, and KaTeX white-on-white text). Attackers made Duo suggest malicious code, share malicious links, and inject rogue HTML — including an <img> tag that exfiltrated private source code to an attacker's server when a victim viewed the response.
Damage
Remote prompt injection let attackers steal source from private projects, manipulate code suggestions shown to others, and even exfiltrate undisclosed zero-day details — all through Duo Chat. GitLab patched it by blocking unsafe external HTML tags.
Classification
- Agent
- GitLab Duo
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.