< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

GitLab launches AI‑agent 19.2 release and patches 13 critical security flaws

GitLab announced the 19.2 version of its DevSecOps platform on 16 July 2026, adding AI‑agent‑driven automation for security and code review. New features include automated dependency‑scan remediation that creates merge requests, a Security Review flow that highlights logical defects, the GitLab Duo CLI for agent management, and customizable YAML‑based workflows. An AI audit event system records agent activity for compliance, and a new access‑control module governs which agents can run where. The release is positioned as a response to the “AI paradox,” where AI‑generated code outpaces traditional security checks.

On 29 July 2026 GitLab also issued patches (versions 19.2.1, 19.1.3 and 19.0.5) fixing 13 vulnerabilities across Community and Enterprise editions. Highlights include CVE‑2026‑6267 in GitLab Workhorse, which could let authenticated developers retrieve internal data, and CVE‑2026‑12436, a mass‑assignment flaw in the Pipeline Schedule API that could allow unauthorized pipeline modifications. Other fixes address denial‑of‑service risks, cross‑site scripting, and token‑generation errors in Duo workflows. GitLab urges all self‑managed users to upgrade immediately, noting that its hosted service already runs the patched code.

Entities

CVE-2026-6267 · GitLab · GitLab Duo CLI · Manav Khurana