Executive brief
GitLab's AI Gateway component, which integrates with cloud AI services like Google Vertex AI and AWS Bedrock, contains a vulnerability that allows authenticated users with Duo Agent Platform access to intercept and redirect model requests to attacker-controlled servers. An attacker could exploit this to steal cloud service credentials, potentially compromising all AI inference requests and associated cloud resources.
Technical details
The vulnerability exists in GitLab AI Gateway's model metadata handling, where insufficient validation of metadata parameters allows authenticated users to craft malicious model configurations. An attacker with Duo Agent Platform access can inject a crafted endpoint URL into model metadata, causing the gateway to redirect all model requests to an external server under their control. This enables interception and exfiltration of Google Vertex AI or AWS Bedrock cloud service credentials that would normally be transmitted to legitimate cloud endpoints. The vulnerability affects AI Gateway versions 18.9.0–19.0.12, 19.1.0–19.1.7, and 19.2.0–19.2.2, with patches available in later releases.
Affected products
- GitLab AI Gateway 18.9.0 to 19.0.12, 19.1 to 19.1.7, 19.2 to 19.2.2
Timeline
- 2026-08-27: disclosed
- other: CVE-2026-19889 published