Cross-origin context poisoning
Cross-origin context poisoning, or XOXO, is an inference-time attack on AI coding assistants that automatically combine code from different files, projects or contributors. An attacker places a functionally equivalent but adversarially chosen transformation in shared code. When the assistant later retrieves that code as context for a different task, lexical or structural cues can steer it toward buggy or vulnerable output even though the changed source still behaves correctly.
Origin and context
Štorek and colleagues introduced XOXO in March 2025 and published a revised study at ACL 2026. They also released code and experiment instructions. A later independent systematization of coding-assistant attacks classified XOXO as a semantic attack modality, alongside but distinct from explicit instruction injection. Earlier security research had shown that neural code completion can be poisoned during training; XOXO shifts the manipulation to context gathered at inference time.
Why it matters
Code review and tests can accept a rename or reordered independent statement because program behavior is unchanged, while the coding model may still react to the altered surface form. That creates a split between software semantics and model behavior. Provenance-aware context collection, visibility into retrieved snippets, trust boundaries, generated-code review and security testing therefore matter even when every contextual file compiles and passes tests. None of those controls alone establishes that a completion is safe.
Example
In the paper's Copilot demonstration, a collaborator renamed a variable in shared Django code without changing its function. When another developer later requested a search feature, the retrieved context led tested Copilot versions to suggest an SQL-injection-vulnerable implementation. This was one controlled scenario, not a claim that the variable name always triggers the flaw; the authors report that the specific issue appeared to be fixed after disclosure.
How it differs
Indirect prompt injection
Indirect prompt injection usually places adversarial instructions in content the model consumes. XOXO instead uses semantics-preserving code changes without an explicit malicious instruction; both exploit untrusted context, but their payload and evaluation assumptions differ.
Memory and context poisoning
Memory and context poisoning is a broader category covering corrupted retained or retrievable state. XOXO is specific to mixed-origin code context in coding assistants and need not persist in an agent's long-term memory.
Data poisoning
Training-data poisoning changes examples used to train or fine-tune a model. XOXO leaves model weights unchanged and manipulates source code that is selected as context during use.
Maturity and evidence
Maturity is rated 3. The named attack has a peer-reviewed ACL long paper, public reproduction materials and independent inclusion in a 2026 coding-assistant security taxonomy. Its boundary and threat model are concrete enough for a durable entry. Maturity 4 would overstate the evidence: there is no independent replication of the headline results, deployed prevalence is unknown, and assistant architectures and defenses continue to change.
Limits and open questions
Published success rates are conditional on the study's Python benchmarks, sampled contexts, models, prompts, decoding settings, transformation set and query budgets. Most tests simulated generic context gathering; the end-to-end product demonstration was one scenario. The attacker is assumed to have commit access, knowledge of the victim workflow and enough access to reproduce the environment locally. Transfer across contexts is not guaranteed. Treat proposed mitigations as defense-in-depth ideas, not certified or comprehensive protection.
Related terms
References
- XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding AssistantsAssociation for Computational Linguistics · 2026-07 · class A
- XOXO paper, arXiv version 4 full textŠtorek et al. / arXiv · 2026-04-20 · class A
- XOXO Attack Reproducibility PackageXOXO authors · 2026 · class B
- Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol EcosystemsInternational Journal of Open Information Technologies · 2026 · class B
- You Autocomplete Me: Poisoning Vulnerabilities in Neural Code CompletionUSENIX Association · 2021-08 · class A
- OWASP Top 10 for Agentic Applications 2026 — ASI06: Memory & Context PoisoningOWASP GenAI Security Project · 2025-12-09 · class A
Last updated: 2026-09-07