GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Executive Summary
GitLab has released patches for a critical flaw in its AI Gateway that could allow a logged‑in user with Duo Agent Platform access to execute arbitrary commands on the gateway under certain conditions. The vulnerability affects self‑hosted GitLab instances and is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-02T17:33:31+00:00 - Category: vulnerabilities
Original Description: A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
"Those who are free of resentful thoughts surely find peace."
— Buddha