GitLab AI Gateway Critical RCE: Patch Self-Hosted Now
A critical flaw in GitLab's AI Gateway lets attackers run arbitrary commands on self-hosted instances. GitLab urges immediate patching.

GitLab has patched a critical remote code execution vulnerability in its AI Gateway service, rated CVSS 9.9. Self-hosted deployments need to update now.
What to do
Check GitLab’s security advisory page for the patched release and affected version range. Update, then verify the AI Gateway service restarted cleanly. If you cannot patch today, disable or network-isolate the AI Gateway until you can apply the fix.
What the flaw is
GitLab’s AI Gateway routes requests between a self-hosted GitLab instance and external AI backends, including code completion and chat features. A flaw in the Gateway lets an attacker with network access execute arbitrary commands on the host. CVSS score is 9.9 and the severity rating is critical, per The Hacker News and BleepingComputer. No CVE was published at time of writing.
Who is affected
Organizations running self-hosted GitLab with AI Gateway enabled. GitLab.com is hosted infrastructure managed by the company, and the advisory specifically calls out self-hosted servers as the affected environment. Self-hosted operators own their upgrade timelines and need to act. If you have AI-assisted features turned on in your deployment, treat the Gateway as present and this flaw as urgent.
Priority call
Patch this before end of day. CVSS 9.9 unauthenticated RCE on a network-reachable service sits at the top of the remediation list. For reference, CVE-2026-85706, a CVSS 10 GitLab path traversal, saw exploitation attempts the same day the patch dropped.
If you updated recently, pull the last 48 hours of AI Gateway process logs and look for unexpected process launches or outbound connections from that service.
Related: GitLab path traversal hits KEV, GitLab package registry RCE.
Found this useful? Share it.

