GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: Duo AI troubleshooting exposes CI/CD variable values from debug job traces

CVSS 7.7CVE-2026-92470Control plane, storage & DevOpscurated

Impact

Missing authorization checks in the Duo AI troubleshooting feature let an authenticated user read sensitive CI/CD variable values out of debug-mode job traces. For a fleet whose builds and deploys run through GitLab, those variables are typically the registry credentials, cloud and Kubernetes service-account tokens, and signing keys that the pipeline uses to push images and reconcile clusters - so the payoff is credentials into the GPU cluster's supply chain rather than anything on the GPU node itself. Exposure is limited to jobs that ran with debug tracing enabled.

Who can reach it

Any authenticated GitLab user who can reach the Duo troubleshooting feature on affected projects; low privileges, network-reachable, no user interaction.

What to do

Upgrade to GitLab EE 19.2.7, 19.3.3 or 19.4.1 (affected: 18.7 up to those releases). Self-managed instances: patch and restart GitLab. Treat any CI/CD variable that appeared in a debug trace on an affected version as exposed and rotate it - the upgrade does not undo prior disclosure.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.