GitLab released a patch for a critical vulnerability in its AI Gateway that enables authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway instances. The company assigned the flaw a CVSS score of 9.9, indicating severe risk.
The AI Gateway serves as the connection layer between GitLab instances and AI models. The vulnerability affects only organizations operating self-hosted gateway deployments. Users with Duo Agent Platform access can exploit the flaw under specific conditions to run commands on the affected gateway infrastructure.
GitLab addressed the issue in gateway versions 19.2.4, 19.3.2, and 19.4.1. Organizations running self-hosted AI Gateway instances should upgrade immediately to one of these patched versions to eliminate exposure.
The advisory did not specify whether the vulnerability has been exploited in the wild or provide technical details about the underlying cause. Organizations using GitLab's cloud-hosted gateway services are not impacted by this flaw, as the vulnerability only affects self-managed deployments.
