GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines
ID: 68c69675-5e72-5ffb-b5de-6da1a16fe9a1
STIX ID: report--68c69675-5e72-5ffb-b5de-6da1a16fe9a1
Feed Name: GBHackers
GitLab released security updates addressing seven vulnerabilities across Community and Enterprise Editions, highlighted by CVE-2026-18252 (CVSS 7.3) in the Duo Claude AI agent that can allow authenticated Developers to execute arbitrary commands within CI pipelines. Self-managed instances running affected versions should upgrade immediately to the specified patched releases; administrators are advised to review CI logs, inspect agent and pipeline configurations, rotate exposed credentials if needed, and enforce least-privilege on runners. The advisory also lists several medium- and low-severity issues affecting pipeline policy enforcement, background-job processing, provisioning, and approval rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
