Story perspectives
GitLab AI Assistant Vulnerabilities Exposed; Swift Fix Implemented
5/23/2025
26 3
1 of 1
Story summary
- Researchers at Legit Security uncovered serious vulnerabilities in GitLab's AI assistant, Duo. Attackers could exploit hidden prompts in comments and code, risking the leak of private source code and the injection of harmful HTML. GitLab has swiftly addressed these issues, underscoring the critical importance of viewing AI tools as potential threats in software development.
