GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
The Hacker News
MAY 22, 2025
Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into its responses, which could then be used to direct victims to malicious websites.
Let's personalize your content