DKDKCISSPSearch
AI Security

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .

DKCISSP News DeskThe Hacker News2 Oct 2026, 11:03 pm
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .

Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.

GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.

To update a Docker deployment , stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.

The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.

Self-managed customers can instead host their own gateway , an option GitLab offers for keeping AI request and response data inside the customer's own environment.

A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway.

A logged-in user with Duo Agent Platform access could have used the flaw to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said.

In February, GitLab fixed another gateway flaw , CVE-2026-1868, which it also rated 9.9.

A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials.

What happened

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .

Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.

What changed

GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.

To update a Docker deployment , stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.

Who is affected

The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.

Self-managed customers can instead host their own gateway , an option GitLab offers for keeping AI request and response data inside the customer's own environment.

Why it matters

A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway.

A logged-in user with Duo Agent Platform access could have used the flaw to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said.

Technical details

In February, GitLab fixed another gateway flaw , CVE-2026-1868, which it also rated 9.9.

A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials.

Cybersecurity and Infrastructure Security Agency (CISA) added an assessment to the CVE record on October 2 that lists exploitation as "none." CISA's other two values cover a public proof of concept and active exploitation.

Response

GitLab strongly recommends that those customers update immediately.

The gateway is installed as its own Docker image or Helm chart and has its own update steps.

What security teams should do

The advisory also gives no way to check whether a gateway was attacked before it was updated.

No workaround is listed for gateways that cannot be updated yet.

Attribution

The Hacker News: A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 amAI Threats Top Cybersecurity Preparedness Gap, PwC FindsInfosecurity Magazine · 1 Oct 2026, 3:00 pm