GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.

The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.

The flaw

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI learns the “dark art” of RFIC design

AI learns the “dark art” of RFIC design Source: Hacker News

Australian energy retailers must provide three hours of free daytime electricity

Australian energy retailers must provide three hours of free daytime electricity Source: Hacker News

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler