GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Cybersecurity · October 3, 2026

Cybersecurity·thehackernews.com

GitLab has shipped a fix for a critical, CVSS 9.9-rated bug in its AI Gateway, the component that links self-hosted GitLab instances to AI models. A logged-in user with access to the Duo Agent Platform could abuse the flaw to execute commands on the gateway itself under the right conditions. Only organizations running their own gateway are affected, and upgrading to gateway versions 19.2.4, 19.3.2, or 19.4.1 closes the hole.

// source: thehackernews.com ↗

← Back to Blog