Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
GitLab AI: Safe Code Turned Malicious - Research - News Directory 3

GitLab AI: Safe Code Turned Malicious – Research

May 27, 2025 Catherine Williams Tech
News Context
At a glance
  • AI-assisted developer tools,marketed‍ as essential for software engineers,can be easily manipulated by malicious actors.
  • Legit ⁢researchers demonstrated how Duo could be tricked into inserting malicious code into a script.This attack, triggered by prompt injections, can also expose private code and vulnerability details.
  • Prompt injections, a common chatbot exploit, involve embedding malicious instructions into content the chatbot processes.
Original source: arstechnica.com

AI developer tools are vulnerable. This research exposes how GitLab’s Duo chatbot, designed to streamline growth, can be manipulated to insert malicious code. Researchers found that prompt injections, a common ⁤chatbot exploit, can trick AI assistants into unfriendly actions, exposing private code and vulnerability details. Malicious actors leverage merge requests, commits, and source code to mislead the AI, highlighting the risks when AI is deeply integrated into development workflows. Stricter input validation and monitoring interactions ⁣are essential. Stay informed with ⁤News Directory 3 for⁢ tech updates. Discover what’s next for‍ AI security.

Key Points

  • AI-assisted tools can be tricked into unfriendly actions.
  • Prompt ⁤injections exploit chatbot vulnerabilities.
  • Malicious code can be inserted via merge requests.

AI Developer Tools Vulnerable to Code Injection Attacks

Updated May 27,2025

AI-assisted developer tools,marketed‍ as essential for software engineers,can be easily manipulated by malicious actors. ⁢GitLab’s Duo chatbot,⁤ promoted for its ⁢ability to streamline workflows, is among those susceptible to attacks.

Legit ⁢researchers demonstrated how Duo could be tricked into inserting malicious code into a script.This attack, triggered by prompt injections, can also expose private code and vulnerability details. The vulnerability arises when users instruct the chatbot to⁤ interact with external content, such as a merge request.

Prompt injections, a common chatbot exploit, involve embedding malicious instructions into content the chatbot processes. large ⁤language model-based⁣ assistants readily follow instructions from various sources, including those controlled by attackers. Attacks targeting Duo utilized merge requests, commits,⁤ bug descriptions, and source code to mislead the AI.

“This vulnerability highlights the double-edged nature of AI assistants like GitLab Duo: when deeply integrated ⁢into development workflows, they inherit not just context—but risk,” Legit researcher Omer Mayraz said.

Mayraz added that hidden instructions in project content can manipulate Duo’s behaviour, exfiltrate private source code, and leverage AI responses for harmful outcomes. The incident underscores the need‍ for robust security measures in AI-powered development environments ⁣to prevent code injection and data breaches.

What’s next

Developers should exercise caution when using AI tools ‍and carefully review any code generated or modified by these systems. implementing stricter input validation and monitoring AI interactions can ⁢help mitigate the ⁢risk of prompt injection attacks and protect sensitive data.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • TikTok Algorithm Amplifies Health Misinformation on Paracetamol and Autism
  • Timeline of Cornell Fraternity Gang Rape Allegations and Investigation

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com