Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GitLab's remediation seems a bit sketchy at best.


The whole "let's put LLMs everywhere" thing is sketchy at best.


I wonder what is so special about onerror, onload and onclick that they need to be positively enumerated - as opposed to the 30 (?) other attributes with equivalent injection utility.


That was my thought too. They didn’t fix the underlying problem, they’ve just patched two possible exfiltration methods. I’m sure some clever people will find other ways to misuse their assistant.


I'm pretty sure they vibecoded the whole thing all along




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: