GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Summary

GitLab has released patches for a critical vulnerability in its AI Gateway that could allow a logged-in user with Duo Agent Platform access to execute commands on the gateway. This flaw specifically affects organizations hosting their own AI Gateway and is now fixed in updated versions.

IFF Assessment

FOE

This vulnerability allows for unauthorized command execution, which is a direct threat to the security and integrity of GitLab instances and their hosted AI models.

Severity

9.0 Critical (AI Estimated)

The CVSS score is estimated to be high due to the critical nature of command execution, potential for privilege escalation, and impact on self-hosted servers.

Defender Context

Defenders need to ensure their self-hosted GitLab AI Gateway instances are updated to the patched versions (19.2.4, 19.3.2, and 19.4.1) to mitigate the risk of unauthorized command execution. This highlights the importance of timely patching for infrastructure components, especially those integrating with AI services.

Read Full Story →