Last seen May 23, 2025

AI Prompt Injection Vulnerability

A critical indirect prompt injection vulnerability was discovered in GitLab Duo Chat, an AI-powered coding assistant, allowing attackers to embed hidden instructions within project content. This flaw enabled the exfiltration of private source code, confidential zero-day vulnerabilities, and the injection of malicious HTML/JavaScript into AI-generated responses.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A critical indirect prompt injection vulnerability was discovered in GitLab Duo Chat, an AI-powered coding assistant, allowing attackers to embed hidden instructions within project content. This flaw enabled the exfiltration of private source code, confidential zero-day vulnerabilities, and the injection of malicious HTML/JavaScript into AI-generated responses.

Why This Matters

Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.

Exposure

My AI Stack Exposure

Exposure unknown

Recommended Response
Last Seen

May 23, 2025 05:30

Exposure reason: This incident does not currently match a technology in My AI Stack.

Exploitation status: UNKNOWN

Primary entities:

Prompt InjectionRemote Code ExecutionEnabled AttackersGitLab Duo VulnerabilityHidden PromptsHijack AI Responses

Timeline

  • Incident first seen
    May 23, 2025 05:30

    BugSkan first recorded this incident.

  • GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts - The Hacker News
    May 23, 2025 05:30

    thehackernews.com · Research

Sources

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts - The Hacker News

thehackernews.com · May 23, 2025 05:30

A critical indirect prompt injection vulnerability was discovered in GitLab Duo Chat, an AI-powered coding assistant, allowing attackers to embed hidden instructions within project content. This flaw enabled the exfiltration of private source code, confidential zero-day vulnerabilities, and the injection of malicious HTML/JavaScript into AI-generated responses.

Open publisher source

My AI Stack Match

Want personalized relevance?

Create an account to see which incidents overlap with your AI stack.

← Back to incident intelligence