Executive brief
GitLab Enterprise Edition contains a vulnerability in its AI-powered Duo Chat feature that allows authenticated users to bypass security controls and extract sensitive configuration data and credentials from the Advanced Search system. An attacker with legitimate access to Duo Chat can craft specially designed requests to expose database connection strings, API keys, and other secrets that should be protected, potentially leading to further system compromise or unauthorized access to integrated services.
Technical details
The vulnerability is a deserialization and object lookup flaw in GitLab EE's GraphQL API, specifically in the Duo Chat subscription handling. An authenticated user can exploit improper serialization filtering in GraphQL subscription arguments to bypass intended access controls and perform arbitrary server object lookups, gaining access to Advanced Search instance configurations and credentials. The attack requires authentication with Duo Chat access but no additional user interaction. The vulnerability affects GitLab EE versions 18.3 through 19.3 with patches available in 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2. The flaw enables information disclosure of sensitive operational data that could be leveraged for lateral movement or supply chain attacks on integrated systems.
Affected products
- GitLab GitLab EE 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2
Timeline
- 2026-09-12: disclosed: Vulnerability published and patched