GitLab warns of critical AI Gateway vulnerability allowing command execution
A critical vulnerability in GitLab's AI Gateway that could allow attackers to execute arbitrary commands on affected instances.
20 articles
A critical vulnerability in GitLab's AI Gateway that could allow attackers to execute arbitrary commands on affected instances.
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has...
GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute a...
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab...
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instance...
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor securi...
These email addresses, part of GitLab's "Email work item to this project" feature, contain long-lived tokens that act as credentials.
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and...
A long-lived GitLab incoming email token embedded in project email addresses for the “Email work item” feature can be exploited to push attacker-controlled c...
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name,...
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab ha...
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresse...
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.
The U.S.
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
The U.S.
The flaw could enable sensitive files to be read with just an HTTP request.
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately.
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Expl...
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Co...