GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.

The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.

The flaw

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 29.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 106 requests (recent log) 216.73.216.208 — 41 requests (recent log) 15.235.206.118 — 35 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 16.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 94.154.46.249 — 2204 requests (recent log) 34.23.43.31 — 2073 requests (recent log) 89.167.35.212 — 799 requests (recent

Framework discloses data breach via Metabase 0-day

Framework discloses data breach via Metabase 0-day Source: Hacker News