CRITICALAdvisoryOct 04, 2026
Action required
Immediately identify and patch all self-hosted GitLab AI Gateway instances to versions 19.2.4, 19.3.2, or 19.4.1. Hunt for exploitation attempts targeting Duo Agent Platform access and monitor for suspicious command execution in AI Gateway logs.
Affected products
GitLabGitLab AI GatewayGitLab Duo
CVE IDs
Linked articles