important · RCE
A normal GitLab Duo user can escape custom-flow templates and execute commands on a self-hosted AI Gateway.
Affects
GitLab Self-Hosted AI Gateway, the service that brokers GitLab Duo model and agent requests in self-managed installations.
The attacker needs a valid GitLab account with Duo Agent Platform access in a deployment using a self-hosted AI Gateway.
Detail and 2 sources
Crafted custom-flow configuration escapes the prompt-template sandbox and executes operating-system commands in the gateway’s service context.
The affected deployment intersection is narrow; GitLab published fixed releases, but the fix was not read for this brief.