GitLab's AI Gateway Had a 9.9 Flaw — Here's What It Means for You

·
Listen to this article~4 min
GitLab's AI Gateway Had a 9.9 Flaw — Here's What It Means for You

GitLab patched a critical 9.9-severity flaw in its AI Gateway that could let users run commands on self-hosted servers. Here's who needs to act and how.

### The Short Version GitLab just patched a nasty one. A critical flaw in its AI Gateway — scoring a 9.9 out of 10 on the severity scale — could let a logged-in user with Duo Agent Platform access run commands on the gateway itself. Yeah, that's the kind of thing that makes sysadmins sit up straight. But here's the good news: this isn't a fire drill for everyone. Only organizations that host their own gateway need to move. If you're on GitLab's cloud, you can breathe. ### Wait, What Even Is the AI Gateway? Think of it as the bridge between your GitLab instance and the AI models it talks to. Every time Duo spins up a suggestion, answers a question, or runs an agent task, that request crosses the gateway. So when something goes wrong there, it's not just an AI hiccup. It's a doorway. And in this case, the door was cracked open just enough for someone with the right access to slip through and execute commands. ### Who's Actually at Risk? This is where it gets specific — and honestly, kind of reassuring for most people. - You're affected if you self-host your AI Gateway - You're affected if users have Duo Agent Platform access - You're NOT affected if you rely on GitLab's managed cloud gateway The flaw requires a logged-in user with specific permissions. So it's not a random stranger on the internet poking at your server. It's someone who already has a foothold — which still matters, because insider risk and compromised accounts are very real. ### The Fix Is Already Out GitLab didn't sit on this. Patched versions are live: - 19.2.4 - 19.3.2 - 19.4.1 If you're running a self-hosted gateway on anything older, upgrade. Seriously. This isn't a "we'll get to it next sprint" situation. > "The best time to patch was the day it dropped. The second best time is right now." — every security engineer, ever ### Why This Matters Beyond GitLab Here's the bigger picture, and it's worth sitting with for a second. AI gateways are becoming the new perimeter. They hold credentials, they route sensitive prompts, and they sit between your code and third-party models. When a gateway gets a 9.9, it's a reminder that AI infrastructure isn't a side project anymore. It's core attack surface. The same way we learned to lock down CI/CD pipelines, we now have to treat AI plumbing with the same paranoia. ### What You Should Do Today A quick checklist: - Check your gateway version — if it's below 19.2.4, patch now - Audit who has Duo Agent Platform access - Review logs for unusual command activity - Subscribe to GitLab's security advisories so you're not caught off guard next time That last one sounds boring, but it's the difference between reading about a flaw and living through one. ### The Takeaway A 9.9 vulnerability is scary on paper. But GitLab moved fast, the fix is straightforward, and most teams aren't even in the blast radius. If you self-host, patch. If you don't, file this away as a reminder that AI gateways deserve a spot on your security radar. The tools are getting smarter. So are the people trying to break them. Stay ahead of both.