iCloud Spoofing, Phishing AI Experts, & The Adblocker Spyware Crisis
Zero Hour Tech analyzes hidden cyber threats: $15K iCloud spoofing bugs, targeted AI policy phishing, adblocker surveillance, and Kiteworks patches.
GitLab patches a critical 9.9 severity AI Gateway RCE vulnerability impacting self-hosted servers. Learn the mitigation steps and version upgrades.
Senior Technology Analyst
GitLab patches a critical 9.9 severity AI Gateway RCE vulnerability impacting self-hosted servers. Learn the mitigation steps and version upgrades.
GitLab has rushed out emergency patches for a critical vulnerability carrying a 9.9 CVSS severity score, impacting self-hosted instances utilizing the GitLab AI Gateway. Tracked as an unauthenticated or authenticated remote command execution (RCE) vector depending on deployment configurations, the flaw resides within how the gateway handles serialized inputs and forwards operational payloads to internal agent execution pipelines.
Organizations leveraging cloud-native or bare-metal deployments of the GitLab Duo Agent Platform are urged to audit their infrastructure immediately. While managed instances hosted directly by GitLab infrastructure have already received automated patches, self-hosted administrators must manually intervene to prevent complete cluster compromise.
The GitLab AI Gateway serves as an intermediary translation layer between local GitLab instances and upstream Large Language Model (LLM) providers, handling everything from code completions to security vulnerability summaries. Because this service sits at the intersection of untrusted user instructions and backend execution environments, any compromise of the gateway process rapidly escalates into host-level container breakouts or direct operating system execution.
The root cause of the vulnerability stems from insufficient input sanitization within the agent processing modules. Specifically, when an authorized user—or an attacker who has hijacked an active session with specific Duo Agent capabilities—submits crafted payloads, the gateway fails to validate parameter constraints before handing execution strings to system shells or dynamic interpreters.
# Example of a vulnerable docker-compose configuration for self-hosted AI Gateway
version: '3.8'
services:
gitlab-ai-gateway:
image: registry.gitlab.com/gitlab-org/ai-assisted/model-gateway:v19.2.0
environment:
- PORT=8080
- MODEL_GATEWAY_ENV=production
- ENABLE_ADVANCED_DUO_AGENTS=true
ports:
- "8080:8080"
networks:
- internal-net
In misconfigured or default self-hosted setups where the gateway container shares administrative sockets or runs with overly permissive service accounts, an attacker can leverage this deserialization and command injection flaw to execute arbitrary shell scripts. This effectively grants them lateral movement into the wider internal corporate network hosting the CI/CD pipelines.
Engineering teams need to map their current deployments against the fixed releases. The issue has been fully remediated in gateway versions 19.2.4, 19.3.2, and 19.4.1.
| Branch / Release Stream | Vulnerable Versions | Patched Version | Recommended Action |
|---|---|---|---|
| 19.2 Series | < 19.2.4 |
19.2.4 |
Immediate container image pull and restart |
| 19.3 Series | < 19.3.2 |
19.3.2 |
Update helm charts / docker-compose manifests |
| 19.4 Series | < 19.4.1 |
19.4.1 |
Upgrade production clusters |
Failing to update these specific gateway versions leaves the host running the proxy service vulnerable to full system takeover if an adversary gains valid credentials for a Duo-enabled user account.
Sysadmins and SecOps engineers can query their active gateway containers to verify running versions before executing updates. Execute the following command within your container management plane to inspect the active deployment tag:
# Inspect running GitLab AI Gateway container version
docker inspect $(docker ps -q --filter name=ai-gateway) \
--format='{{.Config.Image}}'
Alternatively, if you are running the gateway via Kubernetes and Helm charts, query your release status directly:
# Check Helm release versions in the monitoring namespace
helm list -n gitlab-ai-gateway-system
If the returned image tag falls below the threshold metrics outlined in the remediation matrix, isolate the container network immediately until the patches can be applied.
19.2.4, 19.3.2, or 19.4.1 depending on your active release train.Contributing editor at Zero Hour Tech, specializing in cybersecurity & privacy analysis, vulnerability response, and emerging software paradigms.
View Full Profile & Articles →Zero Hour Tech analyzes hidden cyber threats: $15K iCloud spoofing bugs, targeted AI policy phishing, adblocker surveillance, and Kiteworks patches.
Investigating a malicious macOS installer deploying the CloudSyncD backdoor via a universal Mach-O binary. Learn indicators of compromise and remediation.
Get our concise weekly security briefings covering newly disclosed vulnerabilities, exploit mechanics, and actionable system hardening guides.
100% Privacy guaranteed. One-click unsubscribe at any time.