

@gerikson @rmf Yeah I don’t see how this is a vuln that specifically targets LLMs rather than just git users in general. If the vulnerable command is git checkout BLAH because BLAH has been poisoned from a SHA to a ref, that’s going to affect anyone or anything that issues that command, human or machine, surely?

@rmf I’m not disagreeing with any of that. This is definitely a class of mistake (let’s be generous and call it that) which LLMs are more likely to make than humans in normal circumstances.
But it’s being touted around as an LLM-specific flaw which it isn’t. They do have their specific weaknesses, prompt injection of course still being a major one (e.g. Meta’s AI being persuaded to gzip & copy over its entire filesystem). But this is, if anything, a weakness in git. And I guess not entirely new, either, given that Github (and maybe other hosts) explicitly prevent users from creating a ref that looks like a SHA.