GitLab Duo Workflows API Missing Authorization Vulnerability

Vulnerability

A missing authorization vulnerability has been identified in the GitLab Duo Workflows API, affecting GitLab Enterprise Edition (EE) versions 18.4 prior to 18.5.5, 18.6 prior to 18.6.3, and 18.7 prior to 18.7.1. This vulnerability could have allowed an authenticated user to access and manipulate AI model settings from unauthorized namespaces by altering namespace identifiers in API requests.

Impact

Exploitation of this vulnerability could have led to unauthorized access and modification of AI model settings across different namespaces.

Remediation

Users are advised to upgrade to GitLab versions 18.7.1, 18.6.3, or 18.5.5. Instructions for updating GitLab can be found on the GitLab Update page.

Added: Jan 9, 2026, 10:30 AM
Updated: Jan 9, 2026, 10:30 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
3.1
exploitability
4.8
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.