← Back to blog

GitLab Fixes Critical AI Gateway RCE Vulnerability

A critical command execution flaw in GitLab's self-hosted AI Gateway affects select configurations. Organizations using affected versions should patch immediately.

TL;DR

  • GitLab patched a critical RCE flaw in its AI Gateway component.
  • Only self-hosted gateway instances with specific configurations are impacted.
  • Attackers with authenticated access could execute arbitrary commands.
  • Upgrade to versions 19.2.4, 19.3.2, or 19.4.1 to mitigate risk.
  • Organizations using GitLab's managed AI services are unaffected.

GitLab has addressed a critical remote command execution (RCE) vulnerability in its AI Gateway service. The flaw poses a significant risk to organizations that self-host the gateway and meet specific configuration criteria. The vulnerability allows an authenticated attacker with access to the Duo Agent Platform to execute arbitrary commands on the underlying server.

This issue does not affect users of GitLab’s managed AI services. However, organizations running their own AI Gateway instances should verify their version and apply the necessary patches immediately. GitLab released fixes in versions 19.2.4, 19.3.2, and 19.4.1 to resolve the vulnerability.

Vulnerability Details

  • The flaw resides in GitLab's AI Gateway, which connects GitLab instances to external AI models.
  • It impacts only self-hosted deployments where specific access controls are misconfigured.
  • An authenticated user with access to the Duo Agent Platform can exploit the vulnerability.
  • Successful exploitation leads to arbitrary command execution on the gateway server.
  • The issue received a CVSS score of 9.9, indicating critical severity.

Remediation and Recommendations

  • Organizations using GitLab's managed AI services are not affected.
  • Self-hosted gateway operators should check their current version immediately.
  • Patched versions include 19.2.4, 19.3.2, and 19.4.1—upgrade to one of these.
  • Review access permissions to the Duo Agent Platform to reduce exposure.
  • Monitor logs for unusual activity that may indicate attempted exploitation.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.