GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .
Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.
GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
To update a Docker deployment , stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Self-managed customers can instead host their own gateway , an option GitLab offers for keeping AI request and response data inside the customer's own environment.
A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway.
A logged-in user with Duo Agent Platform access could have used the flaw to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said.
In February, GitLab fixed another gateway flaw , CVE-2026-1868, which it also rated 9.9.
A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials.
What happened
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .
Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.
What changed
GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
To update a Docker deployment , stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
Who is affected
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Self-managed customers can instead host their own gateway , an option GitLab offers for keeping AI request and response data inside the customer's own environment.
Why it matters
A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway.
A logged-in user with Duo Agent Platform access could have used the flaw to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said.
Technical details
In February, GitLab fixed another gateway flaw , CVE-2026-1868, which it also rated 9.9.
A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials.
Cybersecurity and Infrastructure Security Agency (CISA) added an assessment to the CVE record on October 2 that lists exploitation as "none." CISA's other two values cover a public proof of concept and active exploitation.
Response
GitLab strongly recommends that those customers update immediately.
The gateway is installed as its own Docker image or Helm chart and has its own update steps.
What security teams should do
The advisory also gives no way to check whether a gateway was attacked before it was updated.
No workaround is listed for gateways that cannot be updated yet.
Attribution
The Hacker News: A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .
What to watch next
Watch for updated vendor guidance and fixed-version details.