logo

GitLab's AI Assistant Opened Devs to Code Theft

ID: de212adc-0e3b-53a9-a01a-457fda96a5ac

STIX ID: report--de212adc-0e3b-53a9-a01a-457fda96a5ac

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-05-22

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers discovered that GitLab's AI assistant 'Duo' was susceptible to indirect prompt injection and HTML rendering flaws, allowing attackers to hide malicious prompts in code, comments, or merge requests; when Duo processed those inputs it could return executable HTML that a victim's browser would run, enabling exfiltration of private source code and other sensitive platform data. Legit Security reported the issues to GitLab, which implemented fixes to address the HTML rendering vulnerability and mitigations to reduce the risk of malicious responses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.