Close Menu
Versa AI hub
  • AI Ethics
  • AI Legislation
  • Business
  • Cybersecurity
  • Media and Entertainment
  • Content Creation
  • Art Generation
  • Research
  • Tools
  • Resources

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

What's Hot

Gemini 3 for developers: new inference, agent features

December 10, 2025

Accenture and Anthropic partner to power enterprise AI integration

December 10, 2025

Fal secures $140 million to power real-time AI-generated content

December 9, 2025
Facebook X (Twitter) Instagram
Versa AI hubVersa AI hub
Thursday, December 11
Facebook X (Twitter) Instagram
Login
  • AI Ethics
  • AI Legislation
  • Business
  • Cybersecurity
  • Media and Entertainment
  • Content Creation
  • Art Generation
  • Research
  • Tools
  • Resources
Versa AI hub
Home»Research»Researchers make safe code malicious for Gitlab AI developer assistants
Research

Researchers make safe code malicious for Gitlab AI developer assistants

versatileaiBy versatileaiMay 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
#image_title
Share
Facebook Twitter LinkedIn Pinterest Email

Marketers are promoting AI-assisted developer tools as an essential workhole for today’s software engineers. For example, developer platform GitLab claims that the duo’s chatbots can “generate a to-do list immediately” that eliminates the burden of “walking through the water through weeks of commitment.” What these companies don’t say is that these tools are easily fooled by temperament, if not by default, by malicious actors to carry out hostile actions towards their users.

On Thursday, researchers at security firm Regain demonstrated an attack that led the duo to insert malicious code into scripts they were instructed to write. Attacks can also leak private code and sensitive issue data, including details about zero-day vulnerabilities. All you need to do is instruct the chatbot to interact with merge requests from external sources or similar content.

AI Assistant Double-edged Blade

Of course, the mechanism that triggers an attack is a rapid injection. Among the most common forms of chatbot exploits, rapid injection is embedded in content. The chatbot will be asked to interact with emails to answer, calendars to consult with, and web pages to summarise. Large language model-based assistants are keen to follow instructions to receive orders from almost anywhere, including sources that malicious actors can control.

The attacks targeting the duo came from a variety of resources commonly used by developers. Examples include merge requests, commits, bug descriptions and comments, and source code. Researchers have demonstrated how instructions embedded in these sources can lead to misleading duoes.

“This vulnerability highlights the double-edged nature of AI assistants like the GitLab duo. When deeply integrated into the development workflow, it inherits risk, not just the context, but also the risk.” “By incorporating hidden instructions in seemingly harmless project content, we were able to manipulate the duo’s behavior, remove private source code, and demonstrate how AI responses can be exploited for unintended, harmful outcomes.”

author avatar
versatileai
See Full Bio
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAfter being inspired by neuroscience, AI is now inspiring neuroscience research: Dario Amodei
Next Article MD Kazi Shahab Uddin is publishing new research promoting AI
versatileai

Related Posts

Research

New AI research clarifies the origins of Papua New Guineans

July 22, 2025
Research

AI helps prevent medical errors in real clinics

July 22, 2025
Research

No one is surprised, and a new study says that AI overview causes a significant drop in search clicks

July 22, 2025
Add A Comment

Comments are closed.

Top Posts

New image verification feature added to Gemini app

December 7, 20256 Views

Aluminum OS is the AI-powered successor to ChromeOS

December 7, 20255 Views

UK and Germany plan to commercialize quantum supercomputing

December 5, 20255 Views
Stay In Touch
  • YouTube
  • TikTok
  • Twitter
  • Instagram
  • Threads
Latest Reviews

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Most Popular

New image verification feature added to Gemini app

December 7, 20256 Views

Aluminum OS is the AI-powered successor to ChromeOS

December 7, 20255 Views

UK and Germany plan to commercialize quantum supercomputing

December 5, 20255 Views
Don't Miss

Gemini 3 for developers: new inference, agent features

December 10, 2025

Accenture and Anthropic partner to power enterprise AI integration

December 10, 2025

Fal secures $140 million to power real-time AI-generated content

December 9, 2025
Service Area
X (Twitter) Instagram YouTube TikTok Threads RSS
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
© 2025 Versa AI Hub. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?