# GitLab fixes command-execution flaw in self-hosted AI Gateway

_Published Friday, October 2, 2026 at 2:45 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![GitLab fixes command-execution flaw in self-hosted AI Gateway — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXhnbLdlAtkMBrrXYLiOxfbEdXI4PrEIq6dy3SL8Xa5SzPF6if9sf8GGu4PtkUTI3EYQHqBde4cDp4Y60OjgQBmqtZHTlL_gvgvlxNSeZ6nrRnriOmH3m23vq7f2bpylilVl39c_X-RNpvYQlRrC91gU_oHbk6e_ZbZ-7_fglpsQCFoLFp3sHkcn44960/s1700-nu-rw-lo-l85-e365/gitlab-rce.jpg)

GitLab disclosed a critical AI Gateway vulnerability on October 2 that could let a logged-in user with Duo Agent Platform access execute commands on the gateway under certain conditions. The Hacker News reports that fixes are available in gateway versions 19.2.4, 19.3.2 and 19.4.1.

A specially crafted workflow configuration could escape the sandbox used for prompt templates. GitLab urges organizations hosting their own gateway to update immediately; its customer gateways are already patched. CISA lists exploitation as "none." No fixed version is listed for the affected releases below 19.2.4, and the advisory provides no workaround.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html)

---
Canonical: https://techandbusiness.org/newswire/83f25_IIEzLcddC134apqp
Published: 2026-10-02T18:45:57.747Z
Story chronology: 2026-10-02T17:33:31.000Z
Retrieved: 2026-10-02T21:52:57.196Z
Publisher: Tech & Business (techandbusiness.org)
