Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GitLab Duo got hit with an oopsie, "AI agent runs with same privilege to site content as the authenticated user" kinda oopsie where you could just exfiltrate private repo information via a pixel gif.

I knew it would get bad, but this bad already? I yearn for rigor haha



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: