Just in:
Iran and Oman advance Hormuz shipping corridor plan // JOYY Delivers YoY and QoQ Growth in Total Revenues as Diversified Businesses Sustain Strong Momentum // Trump Golden Token redemption claim lacks evidence // Ferrari World stages women-only indoor run // JPMorgan weighs stablecoin as banks rethink digital money // US sanctions deepen pressure on China’s Iranian oil trade // Alibaba insider buying fails to erase dilution fears // US disrupts China-linked hacking platforms targeting agencies // Only 49% of Singaporeans Feel Prepared for the Next Decade // Gulf Intelligence’s 2026 Energy Journalist Award // BJP-SAD alliance shaky as BJP claims big brother role // Knitup unlocks a new era of creator commerce with single-piece premium knit production // SpaceX plans giant Louisiana hub for Starship launches // Dubai Museum of the Future to shut for overhaul // Trump’s high-tariff regime revives Japanese investment in India // From textile waste to runway: Redress Design Award 2026 opens public vote for the next generation of sustainable fashion designers // Sofar Sounds Launches Creative Studio Built Around Its Global Live Music & Experiences Community // Vinhomes Strengthens Its Position at the Forefront of Smart City Development // SenseTime Records First‑Ever Profit in First Half of 2026 “Models + Token Factory + Agent Harness” Framework Unlocks High‑Value Commercialization // Green GSM Philippines launches premium taxi, a 7-seat high-end electric taxi service //

Hidden Prompts in GitLab Duo Expose Source Code to Theft

A critical vulnerability in GitLab’s AI-powered coding assistant, Duo, has exposed private source code repositories to theft through a sophisticated indirect prompt injection attack, cybersecurity researchers have revealed. The flaw, now patched, allowed attackers to embed hidden instructions within project content, leading the AI to leak sensitive data and manipulate its responses.GitLab Duo, introduced in June 2023 and built on Anthropic’s Claude models, is designed to assist developers in writing, reviewing, and editing code. However, researchers from Legit Security discovered that Duo’s deep integration across the DevSecOps pipeline made it susceptible to exploitation. By embedding concealed prompts in areas such as merge request descriptions, commit messages, and code comments, attackers could manipulate Duo’s behavior without direct interaction.

The attack exploited Duo’s ability to process and render Markdown content directly in the browser. This feature, while enhancing user experience, introduced client-side injection risks. Malicious actors could inject untrusted HTML into Duo’s responses, potentially redirecting users to phishing sites or executing harmful scripts. In some cases, hidden prompts could instruct Duo to exfiltrate private source code to attacker-controlled servers.

Omer Mayraz, a senior security researcher at Legit Security, emphasized the severity of the vulnerability. “Duo analyzes the entire context of the page, including comments, descriptions, and the source code—making it vulnerable to injected instructions hidden anywhere in that context,” he explained. This comprehensive analysis capability, while beneficial for development, inadvertently expanded the attack surface.

The researchers demonstrated that attackers could further obfuscate malicious prompts using techniques like Base16 encoding, Unicode smuggling, and rendering text in white to evade detection. These methods made it challenging for developers and security tools to identify and mitigate the embedded threats.

Prompt injection, particularly in AI systems, has been recognized as a significant security concern. The Open Worldwide Application Security Project ranked it as a top risk in its 2025 OWASP Top 10 for LLM Applications report. Unlike direct prompt injection, where attackers input malicious commands directly, indirect prompt injection involves embedding harmful instructions within content that the AI processes, making it harder to detect and prevent.

Following responsible disclosure on February 12, 2025, GitLab addressed the vulnerabilities. The company implemented foundational prompt guardrails, including structured prompts, enforced context boundaries, and filtering tools, to reduce the risk of such attacks. However, GitLab acknowledged that while these measures mitigate risks, they do not eliminate all vulnerabilities, especially against sophisticated attacks.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…