Impact
The GitLab AI Gateway component contains a flaw in its template engine that fails to properly neutralize special elements. An authenticated user with Duo Agent Platform access can craft a flow configuration that escapes the sandbox and causes the gateway to execute arbitrary commands. The weakness is a classic template injection issue (CWE‑1336), allowing an attacker to gain remote code execution capabilities on the underlying system that hosts the AI Gateway.
Affected Systems
Affected are all GitLab AI Gateway releases from 18.1.6 up to but excluding 19.2.4, from 19.3 before 19.3.2, and from 19.4 before 19.4.1. The vulnerability resides exclusively in the AI Gateway component and applies to installations that grant Duo Agent Platform users permission to modify flow configurations.
Risk and Exploitability
The CVSS base score of 9.9 indicates critical severity, and the exploitability is high because the attacker only needs authenticated Duo Agent Platform credentials, a common role in many organizations. The EPSS value is not available, and the vulnerability is not catalogued in CISA KEV. Thus, the risk is considerable, and organizations should act quickly to patch or otherwise mitigate the flaw.
OpenCVE Enrichment