Close Menu
Versa AI hub
  • AI Ethics
  • AI Legislation
  • Business
  • Cybersecurity
  • Media and Entertainment
  • Content Creation
  • Art Generation
  • Research
  • Tools

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

What's Hot

Gemini 2.5 update from Google Deepmind

May 28, 2025

Kingsoft Cloud (KC) reports mixed results for Q1, AI Business Surges

May 28, 2025

The UK deploys AI to increase Arctic security amid growing threats

May 28, 2025
Facebook X (Twitter) Instagram
Versa AI hubVersa AI hub
Thursday, May 29
Facebook X (Twitter) Instagram
Login
  • AI Ethics
  • AI Legislation
  • Business
  • Cybersecurity
  • Media and Entertainment
  • Content Creation
  • Art Generation
  • Research
  • Tools
Versa AI hub
Home»Research»Researchers make safe code malicious for Gitlab AI developer assistants
Research

Researchers make safe code malicious for Gitlab AI developer assistants

versatileaiBy versatileaiMay 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
#image_title
Share
Facebook Twitter LinkedIn Pinterest Email

Marketers are promoting AI-assisted developer tools as an essential workhole for today’s software engineers. For example, developer platform GitLab claims that the duo’s chatbots can “generate a to-do list immediately” that eliminates the burden of “walking through the water through weeks of commitment.” What these companies don’t say is that these tools are easily fooled by temperament, if not by default, by malicious actors to carry out hostile actions towards their users.

On Thursday, researchers at security firm Regain demonstrated an attack that led the duo to insert malicious code into scripts they were instructed to write. Attacks can also leak private code and sensitive issue data, including details about zero-day vulnerabilities. All you need to do is instruct the chatbot to interact with merge requests from external sources or similar content.

AI Assistant Double-edged Blade

Of course, the mechanism that triggers an attack is a rapid injection. Among the most common forms of chatbot exploits, rapid injection is embedded in content. The chatbot will be asked to interact with emails to answer, calendars to consult with, and web pages to summarise. Large language model-based assistants are keen to follow instructions to receive orders from almost anywhere, including sources that malicious actors can control.

The attacks targeting the duo came from a variety of resources commonly used by developers. Examples include merge requests, commits, bug descriptions and comments, and source code. Researchers have demonstrated how instructions embedded in these sources can lead to misleading duoes.

“This vulnerability highlights the double-edged nature of AI assistants like the GitLab duo. When deeply integrated into the development workflow, it inherits risk, not just the context, but also the risk.” “By incorporating hidden instructions in seemingly harmless project content, we were able to manipulate the duo’s behavior, remove private source code, and demonstrate how AI responses can be exploited for unintended, harmful outcomes.”

author avatar
versatileai
See Full Bio
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAfter being inspired by neuroscience, AI is now inspiring neuroscience research: Dario Amodei
Next Article MD Kazi Shahab Uddin is publishing new research promoting AI
versatileai

Related Posts

Research

“Infinite AI research will lose us before the vast ocean”: CEO

May 24, 2025
Research

A practical playbook for large-scale research

May 24, 2025
Research

Unilever’s R&D head lifts AI, robot lids and breaks the “grease gap”

May 23, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

The UAE announces bold AI-led plans to revolutionize the law

April 22, 20253 Views

The UAE will use artificial intelligence to develop new laws

April 22, 20253 Views

New report on national security risks from weakened AI safety frameworks

April 22, 20253 Views
Stay In Touch
  • YouTube
  • TikTok
  • Twitter
  • Instagram
  • Threads
Latest Reviews

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Most Popular

The UAE announces bold AI-led plans to revolutionize the law

April 22, 20253 Views

The UAE will use artificial intelligence to develop new laws

April 22, 20253 Views

New report on national security risks from weakened AI safety frameworks

April 22, 20253 Views
Don't Miss

Gemini 2.5 update from Google Deepmind

May 28, 2025

Kingsoft Cloud (KC) reports mixed results for Q1, AI Business Surges

May 28, 2025

The UK deploys AI to increase Arctic security amid growing threats

May 28, 2025
Service Area
X (Twitter) Instagram YouTube TikTok Threads RSS
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
© 2025 Versa AI Hub. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?