GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical vulnerability in GitLab’s AI Gateway has been patched, allowing attackers to execute arbitrary commands on self-hosted servers. The flaw, designated as 9.9, was discovered and reported to GitLab by a researcher, who chose to remain anonymous. As a result of the patch, users of self-hosted GitLab installations are advised to update their AI Gateway software as soon as possible.

The vulnerability affects the AI Gateway’s ability to handle certain types of input data, allowing an attacker to inject malicious commands that can be executed on the server with elevated privileges. This is particularly concerning for organizations that have self-hosted servers and use the AI Gateway to manage access controls and automate workflows. In a worst-case scenario, an attacker could gain full control over the affected server.

The AI Gateway uses machine learning algorithms to analyze network traffic and identify potential threats in real-time. However, it appears that these algorithms contain a flaw that allows attackers to bypass certain security checks and inject malicious code into the system. This vulnerability is particularly insidious because it can be exploited by an attacker without requiring any special privileges or knowledge of the underlying system.

The good news for affected users is that the patch has been released and is available for download from the GitLab website. However, users must ensure they have updated their AI Gateway software as soon as possible to prevent potential exploitation. Additionally, organizations should review their security policies and procedures to determine whether any additional measures are necessary to mitigate this type of vulnerability in the future.

The discovery of this vulnerability highlights the ongoing challenges of securing complex systems that rely on machine learning algorithms. As these types of systems become increasingly prevalent, they also create new attack surfaces for malicious actors to exploit. In light of this development, organizations should prioritize regular security audits and updates to their software, as well as implement robust incident response plans to quickly respond to potential breaches.

As a practical takeaway from this story, users are advised to regularly review the security settings on their self-hosted servers and ensure that all necessary patches have been applied. This includes keeping software up-to-date, implementing strict access controls, and monitoring system logs for suspicious activity. By taking proactive steps to secure their systems, organizations can minimize the risk of exploitation and maintain the integrity of their sensitive data.


Source: The Hacker News — 2026-10-02