Home / Oct 04, 2026 / Story
0
#4 The Hacker News general October 02, 2026 at 17:33 UTC

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

By [email protected] (The Hacker News)

AI Summary

GitLab patched a critical 9.9 CVSS vulnerability in its AI Gateway component that could allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers. Fixed versions are 19.2.4, 19.3.2, and 19.4.1; only organizations self-hosting the AI Gateway are affected and must apply patches immediately. The flaw sits at the intersection of AI infrastructure and privilege escalation — a growing attack surface as enterprises deploy AI-integrated DevOps pipelines.

Relevance score: 82.0/100

# More from October 04