Hidden Prompts In Gitlab Duo Expose Source Code To Theft
A critical vulnerability in GitLab's AI-powered coding assistant, Duo, has exposed private source code repositories to theft through a sophisticated indirect prompt injection attack, cybersecurity researchers have revealed. The flaw, now patched, allowed attackers to embed hidden instructions within project content, leading the AI to leak sensitive data and manipulate its responses.
GitLab Duo, introduced in June 2023 and built on Anthropic's Claude models, is designed to assist developers in writing, reviewing, and editing code. However, researchers from Legit Security discovered that Duo's deep integration across the DevSecOps pipeline made it susceptible to exploitation. By embedding concealed prompts in areas such as merge request descriptions, commit messages, and code comments, attackers could manipulate Duo's behavior without direct interaction.
The attack exploited Duo's ability to process and render Markdown content directly in the browser. This feature, while enhancing user experience, introduced client-side injection risks. Malicious actors could inject untrusted HTML into Duo's responses, potentially redirecting users to phishing sites or executing harmful scripts. In some cases, hidden prompts could instruct Duo to exfiltrate private source code to attacker-controlled servers.
Omer Mayraz, a senior security researcher at Legit Security, emphasized the severity of the vulnerability.“Duo analyzes the entire context of the page, including comments, descriptions, and the source code-making it vulnerable to injected instructions hidden anywhere in that context,” he explained. This comprehensive analysis capability, while beneficial for development, inadvertently expanded the attack surface.
The researchers demonstrated that attackers could further obfuscate malicious prompts using techniques like Base16 encoding, Unicode smuggling, and rendering text in white to evade detection. These methods made it challenging for developers and security tools to identify and mitigate the embedded threats.
See also CoreWeave Powers Aston Martin Aramco's AI Cloud StrategyPrompt injection, particularly in AI systems, has been recognized as a significant security concern. The Open Worldwide Application Security Project ranked it as a top risk in its 2025 OWASP Top 10 for LLM Applications report. Unlike direct prompt injection, where attackers input malicious commands directly, indirect prompt injection involves embedding harmful instructions within content that the AI processes, making it harder to detect and prevent.
Following responsible disclosure on February 12, 2025, GitLab addressed the vulnerabilities. The company implemented foundational prompt guardrails, including structured prompts, enforced context boundaries, and filtering tools, to reduce the risk of such attacks. However, GitLab acknowledged that while these measures mitigate risks, they do not eliminate all vulnerabilities, especially against sophisticated attacks.
Notice an issue? Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com . We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- Poppy Seed Market Size, Share, In-Depth Insights, Opportunity And Forecast 2025-2033
- The Dubai Insiders Club Expands Access To Australia And Asia Amid Surge In International Investor Demand
- What Are The Latest Trends In The Europe Steel Market For 2025?
- UK Digital Health Market To Reach USD 37.6 Billion By 2033
- Nowpayments To Participate In Sigma Europe Rome 2025
- Japan Skin Care Products Market Size Worth USD 11.6 Billion By 2033 CAGR: 4.18%
Comments
No comment