GitLab Duo Claude AI Agent の脆弱性 CVE-2026-18252 などが FIX:CI 環境内での任意のコマンド実行

GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines

2026/08/27 gbhackers — GitLab が公表したのは、Community Edition/Enterprise Edition に対するセキュリティ・アップデートのリリースであり、Duo Claude AI Agent に存在する深刻度 High の脆弱性を含む 7 件の脆弱性を修正するものだ。この脆弱性を悪用する認証済みの Developer は、CI (Continuous Integration) 環境内で任意のコマンドを実行する可能性がある。

Continue reading “GitLab Duo Claude AI Agent の脆弱性 CVE-2026-18252 などが FIX:CI 環境内での任意のコマンド実行”