Cybersecurity · October 3, 2026
GitLab has shipped a fix for a critical, CVSS 9.9-rated bug in its AI Gateway, the component that links self-hosted GitLab instances to AI models. A logged-in user with access to the Duo Agent Platform could abuse the flaw to execute commands on the gateway itself under the right conditions. Only organizations running their own gateway are affected, and upgrading to gateway versions 19.2.4, 19.3.2, or 19.4.1 closes the hole.
// source: thehackernews.com ↗