Security Vulnerabilities in AI-Powered Git Pull Request Tools - A Case Study of Qodo Merge
media.ccc.de via YouTube
Free courses from frontend to fullstack and AI
PowerBI Data Analyst - Create visualizations and dashboards from scratch
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Watch a 41-minute conference talk from the 38th Chaos Communication Congress (38C3) exploring critical security vulnerabilities in Qodo Merge, an AI-powered tool for handling git pull requests. Discover how this increasingly popular open-source tool, despite its helpful features like pull request analysis and code improvement suggestions, contains serious security flaws that could lead to privilege escalation on Gitlab, unauthorized write access to Github repositories, and exposure of repository secrets. Learn about the widespread impact on major projects, including government repositories, automotive industry projects, and blockchain systems. Understand the technical details of how Qodo Merge operates, the specific exploitation methods, and essential remediation steps to protect repositories. The presentation also addresses the challenges faced when attempting to report these vulnerabilities and examines the current security posture of the project.
Syllabus
38C3 - AI Meets Git: Unmasking Security Flaws in Qodo Merge
Taught by
media.ccc.de