CyberSecurity News
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
AI summary
GitLab has patched a critical vulnerability in its AI Gateway that could allow a logged-in user with specific access to execute commands on the gateway. The issue affects self-hosted servers and arises under certain conditions when the Duo Agent Platform is used. The AI Gateway is a service that connects a GitLab instance to AI models. Organizations that host their own gateway are the ones that need to take action. The vulnerability has been fixed in versions 19.2.4, 19.3.2, and 19.4.1 of the gateway.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

