Vibe Coding
GitLab's Duo Agent Platform Could Redirect Model Requests to an Attacker-Controlled Endpoint (CVE-2026-19889 / CVE-2026-75871, 8.2)
Two GitLab AI Gateway vulnerabilities published 2026-08-27 let an authenticated user with Duo Agent Platform access redirect outbound model requests to an externally controlled destination, affecting AI Gateway 18.9.0/18.10 through 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. Redirecting the model endpoint means every prompt, and every repo context attached to it, goes to the attacker, and every response comes back trusted. This is GitLab's second agent-surface disclosure in two days after CVE-2026-18252 hit the Claude agent's CI config path.
Source
↳ Follow the thread