Impact
The vulnerability resides in the GitLab AI Gateway component and allows an authenticated user that has Duo Agent Platform access to construct a crafted inline flow configuration that overrides the HTTP Host header. This manipulation enables the user to redirect outbound model requests to an externally‑controlled endpoint, resulting in the disclosure of Google Cloud Vertex cloud service credentials and private signing keys. The primary impact is the compromise of sensitive credentials, exposing integrated cloud services to unauthorized access.
Affected Systems
Affected vendors include GitLab, specifically the GitLab AI Gateway product. All versions from 18.10 up to 19.0.12, from 19.1 up to 19.1.7, and from 19.2 up to 19.2.2 are vulnerable.
Risk and Exploitability
The CVSS score of 8.2 designates this as a High‑severity vulnerability. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector requires authentication and Duo Agent Platform permissions, meaning an insider or compromised internal user could exploit the flaw. Exploitation involves crafting an inline flow configuration, making the influence path both technically feasible and potentially destructive.
OpenCVE Enrichment