Database/AI/ML frameworks & serving
GitLab AI Gateway: crafted Duo flow config escapes the prompt template sandbox into command execution
Impact
An authenticated user with Duo Agent Platform access can supply a flow configuration that breaks out of the prompt template sandbox and runs arbitrary commands on the AI Gateway host. The gateway is the component that brokers model calls for an entire GitLab instance, so it holds the model provider credentials and sees prompts and code from every project that uses Duo. CVSS is 9.9 with a changed scope, meaning the escape reaches beyond the gateway process itself. For an operator this is a self-hosted AI service turning into an execution foothold next to CI runners and source code, reachable by anyone who already has a low-privilege account.
Who can reach it
Any authenticated GitLab user who has access to the Duo Agent Platform, over the network. No administrator role needed.
What to do
Upgrade the AI Gateway to 19.4.1, 19.3.2, or 19.2.4 depending on branch (versions from 18.1.6 up to those releases are affected) and restart the gateway service. For self-managed deployments this is a container image bump and a daemon restart, not a node-level maintenance window; GPU nodes serving the models are not themselves patched. If an upgrade cannot be scheduled immediately, restrict Duo Agent Platform access to trusted users.
References
Related entries
- scikit-learn / joblib: `joblib.load()` executes commands from an untrusted file via `__reduce__`CVE-2020-13092 · scikit-learn / joblibCritical
- PyTorch (`torch.jit.annotations.parse_type_line`): Arbitrary code execution via unsafe `eval` in TorchScript typeCVE-2022-45907 · PyTorch (`torch.jit.annotations.parse_type_line`)Critical
- MLflow: Path traversal prior to 2.3.1CVE-2023-2780 · MLflowCritical
- LangChain (`LLMMathChain`): Prompt injectionCVE-2023-29374 · LangChain (`LLMMathChain`)Critical
- LangChain (PALChain): Arbitrary code execution via `os.system`/`exec` in generated codeCVE-2023-36258 · LangChain (PALChain)Critical
- LangChain (`load_prompt`): Arbitrary code execution from a JSON prompt fileCVE-2023-36281 · LangChain (`load_prompt`)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.