GitLab patches critical 9.9 flaw in self-hosted AI Gateway
GitLab patches a critical vulnerability in its AI Gateway that allows command execution on self-hosted servers. We analyze the impact and measures for SMBs.

GitLab has published a security advisory about a critical vulnerability in its AI Gateway, the component that connects a GitLab instance with artificial intelligence models. The flaw, with a score of 9.9 out of 10, could allow an authenticated user with access to Duo Agent Platform to execute commands on the gateway under certain conditions. The good news is that it only affects organizations that host their own gateway, not those that use the version managed by GitLab.
The issue has been fixed in versions 19.2.4, 19.3.2, and 19.4.1 of the gateway. If your company has a self-hosted AI Gateway, it is imperative to update immediately. Remote command execution is one of the worst possible consequences: an attacker could take control of the server, access sensitive data, or move laterally across the network. Although the flaw requires prior authentication, in an environment with multiple users and elevated permissions, the risk is enormous.
For an SMB, the adoption of AI in its workflows is an opportunity, but it also introduces new attack vectors. The complexity of AI systems, with multiple components and dependencies, makes the exposure surface grow. This incident reminds us that security cannot be an afterthought. At ForgeNEX we insist that AI integration must be accompanied by a thorough review of the architecture and access controls.
What do we recommend from ForgeNEX? First, identify whether your organization uses a self-hosted AI Gateway. If so, apply the updates as soon as possible. Do not wait for the maintenance window: a critical vulnerability gives no respite. Second, review the gateway's access and activity logs to detect possible exploitation attempts. Although there is no evidence of active attacks, prevention is key. Finally, consider implementing the principle of least privilege: limit who can interact with the gateway and with what permissions.
This is not an isolated case. We have recently seen how FortiMail suffered a critical zero-day that allowed arbitrary file write, and how AI is accelerating the emergence of exploits. The lesson is clear: patch management and continuous monitoring are essential. It is not enough to trust that the provider will resolve it; organizations that self-host services must assume their share of responsibility.
Furthermore, the security of AI systems requires a specific approach. It is not just about applying patches, but about understanding how the components interact. For example, the AI Gateway acts as a bridge between GitLab and the models, which makes it a critical point. If an attacker controls it, they could manipulate AI responses, exfiltrate data, or even use the server as a platform for other attacks. That is why we recommend segmenting the network and isolating these services from the rest of the infrastructure.
At ForgeNEX we help SMBs deploy and secure their development and AI tools. If you need advice on how to protect your GitLab instance or want to review your security posture, do not hesitate to contact us. Cybersecurity is a continuous process, and staying up to date with vendor advisories is the first step.
For more information on how AI is changing the threat landscape, you can read our article AI accelerates exploits: your CVE spreadsheet is no longer useful. You may also be interested in AI Security: the defensive mindset is no longer enough.
Source: The Hacker News. Analysis and adaptation: ForgeNEX.