Impact
A server‑side request forgery flaw in the GitLab AI Gateway lets an authenticated user with Duo Agent Platform privileges redirect model requests through crafted metadata to an attacker‑controlled endpoint. This can expose the credentials used by Google Vertex AI or AWS Bedrock, allowing the attacker to access cloud resources and potentially piggyback on the organization’s data environment.
Affected Systems
The flaw affects all GitLab AI Gateway releases from 18.9.0 up to 19.0.12, from 19.1 to 19.1.7, and from 19.2 to 19.2.2. Any installation of these versions is susceptible until a patch is applied.
Risk and Exploitability
The CVSS base score of 8.2 signals a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires valid Duo Agent Platform credentials, so an insider or a compromised user with that access could easily mount the attack. Once the protected endpoints are accessed, an attacker can harvest cloud service credentials and gain broad, potentially unrestricted access to cloud resources.
OpenCVE Enrichment