GitLab Fixes Claude AI Agent Flaw That Could Execute Arbitrary Commands in CI Pipeline
Brief
GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts.
The flaw, tracked as CVE-2026-18252, affects GitLab Enterprise Edition installations and carries a CVSS score of 7.
- The company issued patched versions GitLab 19.
- 1, 19.
- 5, and 19.
- 7 on August 26, 2026.
GitLab strongly urged self-managed customers to update immediately. GitLab. com is already running the corrected software, while GitLab Dedicated customers do not need to take action.
The Duo Claude AI agent processing configuration from a user-controlled source caused the vulnerability. Under certain conditions, an authenticated user with Developer-role permissions could exploit this behavior to make the agent execute arbitrary commands in a CI environment.
