“A hidden comment was enough to make GitLab Duo leak private source code and inject untrusted HTML into its responses.”

A comment hidden in a merge request made GitLab Duo send private source code to an attacker’s server. The instructions were hidden with white-on-white text and Unicode tricks, so a human reviewer never saw them. Legit reported it in February. Any assistant that reads text from strangers and acts on it is an attack surface, and vendors keep bolting them onto repos anyway.