GitLab Duo AI Prompt Hijack
- Researchers found a prompt injection flaw in GitLab Duo Chat assistant.
- Attackers could steal source code and exfiltrate confidential data via hidden prompts.
- Flaw exploited AI’s interpretation of malicious embedded content in code or docs.
- Injection enabled manipulation of AI-generated code suggestions shown to users.
- Vulnerability highlights risks in LLM integrations and AI-driven development tools.
