Tools AI Risk Radar ai-incident-0023
Incident record
GitLab Duo could be pointed at an attacker’s endpoint and hand over cloud model credentials
- Severity
- Critical
- Status
- Patched
- Type
- Data Leak
- Target
- GitLab AI Gateway 18.9.0 to 19.2.2
- Actor
- researcher
- CVE
- CVE-2026-19889
What happened
GitLab fixed two flaws in its AI Gateway that let an authenticated user with Duo Agent Platform access redirect outbound model requests to an endpoint they controlled, exposing the Google Vertex AI or AWS Bedrock credentials underneath. CVE-2026-19889 went through crafted model metadata; the second, CVE-2026-75871, through a crafted request.
GitLab scores both 8.2 high under its own numbering authority, while NVD scores CVE-2026-75871 at 9.6 critical, and the higher reading is the one to plan around: the credentials at risk are for the customer’s own cloud model accounts, not for GitLab. Affected versions run from 18.9.0 through 19.0.12, 19.1 through 19.1.7 and 19.2 through 19.2.2, with the second CVE starting at 18.10.
Sources
- NVD record, CVE-2026-19889nvd.nist.gov/vuln/detail/CVE-2026-19889
- NVD record, CVE-2026-75871nvd.nist.gov/vuln/detail/CVE-2026-75871
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026