Vulnerability  ·  2026-08-27

GitLab Duo Claude AI agent flaw allows arbitrary command execution in CI context

VulnerabilityHigh impactGlobalCVE-2026-18252
GitLab's Aug 26, 2026 patch release fixed CVE-2026-18252 (CVSS 8.7), in which the Duo Claude AI agent's handling of user-controlled CI configuration let a developer-role user achieve arbitrary command execution within CI pipeline infrastructure.
GitLab CI runners frequently hold elevated privileges for build/deploy tasks; a flaw in the AI-agent-driven CI feature turns a routine developer permission level into a software-supply-chain compromise vector across every project using the Duo Claude integration.
The Duo Claude AI agent processes configuration from a user-controlled source (Inclusion of Functionality from Untrusted Control Sphere), allowing an authenticated developer-role user to inject arbitrary commands that execute in the CI job context, typically with elevated runner privileges.
GitLab EE 18.9 before 19.1.7, 19.2 before 19.2.5, 19.3 before 19.3.1
Upgrade to GitLab 19.3.1, 19.2.5, or 19.1.7.
GitLab Patch Release 19.3.1
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →