GitLab has patched a critical vulnerability in its AI Gateway, the component that bridges self-hosted GitLab instances with AI models used by Duo Agent Platform. According to GitLab’s advisory, the flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on the gateway under certain conditions.

The AI Gateway acts as the intermediary service that routes requests from a GitLab instance to backend AI models, handling authentication, inference calls, and agent orchestration for Duo features. Because of this central role, a command execution flaw in the gateway could give an attacker a foothold to pivot deeper into an organization’s infrastructure, potentially exposing source code, credentials, or other sensitive data processed through AI-assisted workflows.

Who Is Affected

GitLab notes that only organizations running their own self-hosted AI Gateway instance need to take action. Customers relying on GitLab’s hosted or SaaS-managed gateway are not affected by this issue, since GitLab has already applied the fix on its managed infrastructure.

Patched Versions

The vulnerability has been resolved in the following AI Gateway releases:

  • 19.2.4
  • 19.3.2
  • 19.4.1

Administrators running self-managed AI Gateway deployments on earlier versions should upgrade immediately. Given the severity rating and the command execution impact, security teams should treat this as a priority patch, particularly in environments where Duo Agent Platform is enabled for broader user groups.

Recommended Actions

  • Identify any self-hosted AI Gateway instances in your environment and confirm their current version.
  • Upgrade to 19.2.4, 19.3.2, 19.4.1, or later as appropriate for your release track.
  • Review access logs for Duo Agent Platform users for unusual activity prior to patching.
  • Audit which users and service accounts have Duo Agent Platform access, since the flaw requires an authenticated session to exploit.

GitLab has not published a CVE identifier in the material reviewed, nor has it indicated evidence of active exploitation. As AI-integrated development tools become more deeply embedded in software supply chains, flaws like this underscore the need to treat AI gateway infrastructure with the same security rigor as production code repositories and CI/CD pipelines.