#4
The Hacker News
general
October 02, 2026 at 17:33 UTC
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
By [email protected] (The Hacker News)
AI Summary
GitLab patched a critical 9.9 CVSS vulnerability in its AI Gateway component that could allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers. Fixed versions are 19.2.4, 19.3.2, and 19.4.1; only organizations self-hosting the AI Gateway are affected and must apply patches immediately. The flaw sits at the intersection of AI infrastructure and privilege escalation — a growing attack surface as enterprises deploy AI-integrated DevOps pipelines.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →