What happened
GitLab's Aug 26, 2026 patch release fixed CVE-2026-18252 (CVSS 8.7), in which the Duo Claude AI agent's handling of user-controlled CI configuration let a developer-role user achieve arbitrary command execution within CI pipeline infrastructure.
Why it matters
GitLab CI runners frequently hold elevated privileges for build/deploy tasks; a flaw in the AI-agent-driven CI feature turns a routine developer permission level into a software-supply-chain compromise vector across every project using the Duo Claude integration.
Attack vector
The Duo Claude AI agent processes configuration from a user-controlled source (Inclusion of Functionality from Untrusted Control Sphere), allowing an authenticated developer-role user to inject arbitrary commands that execute in the CI job context, typically with elevated runner privileges.
Affected systems
GitLab EE 18.9 before 19.1.7, 19.2 before 19.2.5, 19.3 before 19.3.1
Mitigation
Upgrade to GitLab 19.3.1, 19.2.5, or 19.1.7.