GitLab Duo flaw exposed artificial intelligence responses to hidden prompt attacks

A vulnerability in GitLab´s artificial intelligence assistant Duo allowed attackers to hijack responses and exfiltrate sensitive code using indirect prompt injection.

Security researchers have identified a significant vulnerability in GitLab´s artificial intelligence assistant, Duo, which posed serious risks to the integrity and confidentiality of user code and project data. This indirect prompt injection flaw allowed malicious actors to embed hidden prompts that manipulated the responses generated by Duo. As a result, attackers could use these manipulated responses to steal source code from private repositories, influence code suggestions shown to users, and even exfiltrate undisclosed zero-day vulnerabilities without detection.

GitLab Duo is built with Anthropic´s Claude models and provides artificial intelligence-powered code writing, review, and editing capabilities for developers on the platform. The vulnerability was discovered in Duo Chat, part of the GitLab Duo suite, and was reported by Legit Security. The researchers demonstrated how attackers could abuse this indirect prompt injection mechanism by embedding hostile instructions in external data—such as commit messages or issues—that Duo would process unknowingly. This method bypassed traditional security controls because the malicious input did not come from users directly interacting with Duo, but rather from auxiliary project artifacts processed in the background.

Prompt injection is a well-known class of attack in artificial intelligence systems, enabling adversaries to exploit the way large language models (LLMs) interpret and respond to natural language instructions. While direct prompt injection involves a user supplying direct malicious input to an artificial intelligence system, the indirect approach leverages hidden cues buried in related project elements, evading detection mechanisms. The discovery underscores the critical need for ongoing vigilance and innovation in artificial intelligence security. Prompt injection attacks highlight the delicate interface between powerful language models and complex enterprise workflows, emphasizing that artificial intelligence deployments must be continuously hardened and scrutinized for emerging threat vectors. GitLab responded to these findings by addressing the flaw and reinforcing the security measures within Duo to mitigate similar risks in the future.

75

Impact Score

Tesla plans terafab for Artificial Intelligence chips

Tesla is moving toward a large-scale chip manufacturing project to support its autonomous driving roadmap. Elon Musk said the terafab effort for Artificial Intelligence chips will launch in seven days and may involve Intel, TSMC and Samsung.

Timeline traces evolution, civilisation and planetary stewardship

A sweeping chronology links cosmology, evolution, human history and modern environmental risk in a single long view of the human condition. The sequence culminates in contemporary debates over climate change, biodiversity loss and artificial intelligence governance.

Wolters Kluwer report tracks Artificial Intelligence shift in legal work

Wolters Kluwer’s 2026 Future Ready Lawyer findings show Artificial Intelligence has become a foundational tool across law firms and corporate legal departments. The survey points to measurable time savings, revenue growth, and rising pressure to strengthen training, ethics, and security.

Anthropic March 2026 release roundup

Anthropic rolled out a broad set of March 2026 updates across Claude Code, the Claude Developer Platform, Claude apps, and enterprise partnerships. Changes focused on larger context windows, workflow improvements, reliability fixes, visual output features, and new partner enablement programs.

China renews push to lead in technology and Artificial Intelligence

China’s 15th five-year plan elevates science and technology as core national priorities, with a strong emphasis on self-reliance and Artificial Intelligence. The blueprint signals heavier investment, broader industrial support, and a more confident bid to shape global technology standards.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.