Back to all news
Security

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

The Hacker News·October 2, 2026·1 min read
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab patched a critical 9.9-severity flaw in its AI Gateway that could allow a logged-in user with Duo Agent Platform access to run commands on the gateway under certain conditions. The gateway connects GitLab instances to AI models, and only self-hosted gateway organizations need to act. Fixes are available in versions 19.2.4, 19.3.2, and 19.4.1.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store