GitLab warns of critical RCE vulnerability in AI Gateway service
High-severity flaw could allow arbitrary command execution on affected instances

Key Takeaways
- GitLab has identified a critical RCE vulnerability in the AI Gateway service.
- The flaw could allow arbitrary command execution on affected instances.
- Security updates have been released; immediate patching is urged.
- No confirmed reports of active exploitation at the time of reporting.
- Users should update to the latest version to mitigate the risk.
Quick answers
- What happened?
- GitLab has identified a critical remote code execution vulnerability in its AI Gateway service. The flaw requires immediate patching to prevent potential arbitrary command execution on vulnerable instances. Details of active exploitation are currently unreported, but the vendor has urged customers to update to the latest patched version without delay.
- Which products are affected?
- AI Gateway
- What should defenders do?
- Apply the security updates released by GitLab for the AI Gateway service. Update to the latest patched version immediately. Monitor official GitLab security advisories for further details and verification of the vulnerability.
GitLab has warned customers to immediately patch a critical vulnerability in its AI Gateway service. The flaw is classified as a remote code execution (RCE) issue that could allow attackers to run arbitrary commands on vulnerable instances. The company has released security updates addressing the vulnerability and is urging all affected users to apply the patches as soon as possible. At the time of reporting, there are no confirmed reports of active exploitation in the wild, though the severity of the flaw and the urgency of the advisory suggest a potential risk. The vulnerability affects the AI Gateway service component of GitLab instances. Users are advised to check their current version and update to the latest patched release available from GitLab.
Security Details
The vulnerability affects GitLab's AI Gateway service and is classified as a remote code execution flaw. Specific technical details such as the CVE identifier, attack vector, and exploitation status are pending full advisory release. GitLab has released patches and urges immediate updating to the latest version.
Affected products
AI Gateway
Mitigation
Apply the security updates released by GitLab for the AI Gateway service. Update to the latest patched version immediately. Monitor official GitLab security advisories for further details and verification of the vulnerability.
Sources
BleepingComputer
GitLab warns of critical RCE vulnerability in AI Gateway service
Oct 2, 2026 · 16:20
Original link
Related Security News

GitLab Patches Critical AI Gateway Vulnerability Allowing Command Execution
GitLab has released patches to address a critical vulnerability in its AI Gateway component, tracked as CVE-2026-44951. The flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers under certain conditions. The vulnerability affects GitLab AI Gateway versions prior to 19.2.4, 19.3.2, and 19.4.1. Organizations running self-hosted instances are urged to update immediately.


