Vulnerability  ·  2026-09-25

GitLab Duo AI troubleshooting leaks sensitive CI/CD variable values from debug-mode job traces (CVE-2026-92470, CVSS 7.7)

VulnerabilityHigh impactGlobalCVE-2026-92470
GitLab EE versions 18.7-19.2.7, 19.3-19.3.3, 19.4-19.4.1 contain an authorization flaw in the Duo AI troubleshooting feature that under certain conditions lets an authenticated user read sensitive CI/CD variable values from debug-mode job traces due to missing authorization checks. Fixed in 19.2.7/19.3.3/19.4.1.
Duo is GitLab's AI assistant inside the CI/CD platform every organization uses. The AI troubleshooting path leaks protected CI/CD secrets (tokens, credentials) to users who should not see them - turning an AI QoL feature into a credential-exfiltration channel inside the software supply chain.
Authenticated user triggers Duo AI troubleshooting on debug-mode job traces to surface protected CI/CD variable values that missing authorization checks fail to redact.
GitLab EE Duo AI >=18.7 before 19.2.7, 19.3 before 19.3.3, 19.4 before 19.4.1
Upgrade to GitLab 19.2.7/19.3.3/19.4.1 or later.
NVD CVE-2026-92470GitLab patch release 19.4.1
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →