Stop Treating LLM Agents as Trusted Users: Lessons from GitLab CVE-2021-39935

CISA added CVE-2021-39935 to the KEV catalog on February 3, 2026 – a 2021 GitLab SSRF vulnerability now seeing active exploitation. The federal remediation deadline is February 24, 2026. This is worth examining not because it’s novel (GitLab patched it in October 2021), but because the threat model around CI/CD attack surfaces has fundamentally changed … Read more