Impact
GitLab Enterprise Edition versions earlier than 19.2.7, 19.3.3, or 19.4.1 contain an authorization flaw that enables users with developer role permissions to bypass administrator‑configured AI tool governance controls for workflows in namespaces they do not control; this allows developers to override governance restrictions that should prevent unsafe or inappropriate AI usage.
Affected Systems
Affected products are GitLab EE, all installations using GitLab 19.1 up to (but not including) 19.2.7, GitLab 19.3 up to (but not including) 19.3.3, and GitLab 19.4 up to (but not including) 19.4.1. The vulnerable logic applies to any instance of GitLab where the AI tool governance policies are enabled and developer users exist in namespaces without administrative ownership.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the lack of an EPSS score means current exploit probability is unknown; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated developer account and namespace context where governance controls are active; attackers do not need external access to reach the flaw, making it a localized privilege‑escalation scenario that could lead to policy circumvention.
OpenCVE Enrichment