Skip to finding
important · RCE

A normal GitLab Duo user can escape custom-flow templates and execute commands on a self-hosted AI Gateway.

Affects

GitLab Self-Hosted AI Gateway, the service that brokers GitLab Duo model and agent requests in self-managed installations.

The attacker needs a valid GitLab account with Duo Agent Platform access in a deployment using a self-hosted AI Gateway.

Detail and 2 sources

Crafted custom-flow configuration escapes the prompt-template sandbox and executes operating-system commands in the gateway’s service context.

The affected deployment intersection is narrow; GitLab published fixed releases, but the fix was not read for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026