Executive brief
GitLab Enterprise Edition, a platform used for software development and collaboration, contained a vulnerability in its AI-assisted code review feature. An authenticated user could potentially access information from projects they were not authorized to view by manipulating the AI's processing of content. This could lead to the unauthorized disclosure of sensitive source code or project data.
Technical details
A prompt injection vulnerability exists in GitLab Enterprise Edition (EE) within the Duo Code Review (AI-assisted code review) functionality. The issue stems from the improper neutralization of untrusted content processed by the AI, which could be exploited by an authenticated user to bypass authorization boundaries. By providing specially crafted input to the AI reviewer, an attacker could potentially retrieve information from projects they do not have permission to access. The vulnerability affects versions 19.1.x (prior to 19.1.3) and 19.2.x (prior to 19.2.1) and has been patched in versions 19.1.3 and 19.2.1.
Affected products
- GitLab GitLab Enterprise Edition 19.1 before 19.1.3, 19.2 before 19.2.1
Timeline
- 2026-07-29: patched: Fixed in GitLab versions 19.2.1 and 19.1.3
- 2026-07-29: advisory