Glossary · term

Cross-origin context poisoning

Cross-origin context poisoning, or XOXO, is an inference-time attack on AI coding assistants that automatically combine code from different files, projects or contributors. An attacker places a functionally equivalent but adversarially chosen transformation in shared code. When the assistant later retrieves that code as context for a different task, lexical or structural cues can steer it toward buggy or vulnerable output even though the changed source still behaves correctly.

Safety2025-03-18Wave 3 · 2025–26Maturity: 3/5

Origin and context

Štorek and colleagues introduced XOXO in March 2025 and published a revised study at ACL 2026. They also released code and experiment instructions. A later independent systematization of coding-assistant attacks classified XOXO as a semantic attack modality, alongside but distinct from explicit instruction injection. Earlier security research had shown that neural code completion can be poisoned during training; XOXO shifts the manipulation to context gathered at inference time.

Sources: s1, s2, s3, s4, s5

Why it matters

Code review and tests can accept a rename or reordered independent statement because program behavior is unchanged, while the coding model may still react to the altered surface form. That creates a split between software semantics and model behavior. Provenance-aware context collection, visibility into retrieved snippets, trust boundaries, generated-code review and security testing therefore matter even when every contextual file compiles and passes tests. None of those controls alone establishes that a completion is safe.

Sources: s1, s2, s4

Example

In the paper's Copilot demonstration, a collaborator renamed a variable in shared Django code without changing its function. When another developer later requested a search feature, the retrieved context led tested Copilot versions to suggest an SQL-injection-vulnerable implementation. This was one controlled scenario, not a claim that the variable name always triggers the flaw; the authors report that the specific issue appeared to be fixed after disclosure.

Sources: s1, s2

How it differs

Indirect prompt injection

Indirect prompt injection usually places adversarial instructions in content the model consumes. XOXO instead uses semantics-preserving code changes without an explicit malicious instruction; both exploit untrusted context, but their payload and evaluation assumptions differ.

Memory and context poisoning

Memory and context poisoning is a broader category covering corrupted retained or retrievable state. XOXO is specific to mixed-origin code context in coding assistants and need not persist in an agent's long-term memory.

Data poisoning

Training-data poisoning changes examples used to train or fine-tune a model. XOXO leaves model weights unchanged and manipulates source code that is selected as context during use.

Maturity and evidence

Maturity is rated 3. The named attack has a peer-reviewed ACL long paper, public reproduction materials and independent inclusion in a 2026 coding-assistant security taxonomy. Its boundary and threat model are concrete enough for a durable entry. Maturity 4 would overstate the evidence: there is no independent replication of the headline results, deployed prevalence is unknown, and assistant architectures and defenses continue to change.

Sources: s1, s3, s4

Limits and open questions

Published success rates are conditional on the study's Python benchmarks, sampled contexts, models, prompts, decoding settings, transformation set and query budgets. Most tests simulated generic context gathering; the end-to-end product demonstration was one scenario. The attacker is assumed to have commit access, knowledge of the victim workflow and enough access to reproduce the environment locally. Transfer across contexts is not guaranteed. Treat proposed mitigations as defense-in-depth ideas, not certified or comprehensive protection.

Sources: s1, s2

Related terms

References

Last updated: 2026-09-07