# GitLab warns of critical RCE vulnerability in AI Gateway service

DevFeed: [GitLab warns of critical RCE vulnerability in AI Gateway service](<https://devfeed.tech/articles/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service-63853.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/>)

Author: Sergiu Gatlan

Published: 2026-10-02T16:20:05Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Dependency management](<https://devfeed.tech/topics/dependency-management.md>)

Tags: [ai-gateway](<https://devfeed.tech/tags/ai-gateway.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-command-execution](<https://devfeed.tech/tags/remote-command-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [warning](<https://devfeed.tech/tags/warning.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

GitLab disclosed a critical vulnerability in its AI Gateway that could let authenticated users with Duo Agent Platform access execute arbitrary commands through a crafted flow configuration. GitLab released patched versions for self-hosted installations and says customers using its hosted gateway are already protected.

## Source excerpt

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]