GitLab AI Gateway Patch, WSL Containers, and Homarr v2

Homelab Highlights for 2026-10-02: self-hosting and homelab notes worth knowing.

[Audio embed placeholder]

News Roundup

Windows can now run Linux containers inside WSL without Docker

Microsoft introduced wslc, a new command-line tool built into WSL that allows running Linux containers directly, providing an alternative to Docker Desktop on Windows.

Why it matters: This offers a lighter-weight, integrated option for developers on Windows who want to run containers without the overhead or licensing considerations of Docker Desktop.

Source: Microsoft Dev Blogs

AI-Powered Tool Generates Accurate Subtitles for Video

An open-source tool uses AI speech-to-text and translation models to generate subtitle files (.srt) from video audio, with reported 95-100% accuracy and built-in handling for proper nouns across episodes.

Why it matters: This provides a low-cost, automated way to create accurate subtitles for personal media libraries, especially useful for content where subtitles are unavailable or don’t match dubbed audio.

Source: GitHub

WordPress Backdoor Rebuilds Itself After Cleanup Using Multiple Persistence Mechanisms

Researchers detailed a WordPress backdoor, codenamed SC, that uses files, database entries, and shared memory to automatically rebuild itself if any single component is removed.

Why it matters: This ‘self-healing’ malware demonstrates advanced persistence techniques, underscoring the need for comprehensive security measures and thorough incident response for WordPress sites.

Source: The Hacker News

Homarr v2 Released with Custom Widgets, Workshop, and Enhanced Integrations

Homarr v2 introduces Custom Widgets v2, a community Workshop, rebuilt board editing, and Integration Requests that allow features to reuse service connections without exposing underlying credentials.

Why it matters: The update transforms Homarr into a more powerful and extensible central dashboard for homelabs, enabling deeper automation and integration while improving security through credential isolation.

Source: r/homelab

Tool & Software Highlight: GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical vulnerability in GitLab’s self-hosted AI Gateway could allow a logged-in user with Duo Agent Platform access to execute commands on the gateway server. The flaw is fixed in versions 19.2.4, 19.3.2, and 19.4.1.

Why it matters: The AI Gateway manages connections and API keys for AI models. A command execution flaw here could lead to credential theft and lateral movement within your infrastructure, making it a high-priority update for anyone running a self-hosted gateway.

Source: The Hacker News

Sources

Transcript

Host A: Welcome to Homelab Highlights, the show that surfaces practical homelab wins and useful self-hosted tools.

Host A: If you’re running a self-hosted GitLab AI Gateway, there’s a critical patch you need to apply. GitLab disclosed a flaw that lets a logged-in user with Duo Agent Platform access execute commands directly on the gateway server. [conversational] That’s the kind of vulnerability that turns a compromised account into full infrastructure access pretty quickly. The gateway sits between your GitLab instance and AI models like OpenAI or Anthropic, routing requests and managing API keys. A command execution flaw here means an attacker could potentially access those credentials or pivot to other services. The good news: this only affects self-hosted gateways. If you’re using GitLab’s SaaS offering, their infrastructure team has already patched. But if you’ve deployed a gateway in your homelab or data center, you need to update. The patch is available in versions 19.2.4, 19.3.2, and 19.4.1. Check which version you’re running and test the update in a non-critical environment first if you can.

Host B: Right, and the attack does require authentication, so it’s not a zero-click thing. But that’s not much comfort if you have multiple users or service accounts with gateway access. [with emphasis] The timing on this is interesting because we’re seeing more people deploy these gateways specifically to manage costs and keep LLM requests off the public cloud. So if you’ve got one running, it’s probably handling sensitive workloads. Worth checking your logs for any unusual activity around the disclosure date, then getting that update scheduled.

Host B: Let’s move through a few other stories. Microsoft shipped wslc, a new way to run Linux containers on Windows without Docker Desktop. It’s built into WSL and lets you spin up containers directly from the command line. The architecture deep dive on the Microsoft devblogs explains how it works, but the practical takeaway is: if Docker Desktop has been a pain point on your Windows machine—resource usage, licensing questions, whatever—this gives you an alternative. Some folks in the community noted that Podman already works in WSL, so this isn’t solving a completely unsolved problem, but it does remove a dependency if you want to keep your Windows setup lighter.

Host A: Shifting to media and content: there’s a new tool for generating subtitles using AI speech-to-text and translation models. The creator posted on GitHub and Reddit about using ElevenLabs STT and Gemini to transcribe video audio and generate .srt files. The cost is roughly 9 cents per 90-minute video, and the accuracy is solid—95 to 100 percent in most cases. [curious] The interesting part is they built in proper noun handling, so if you’re translating anime or foreign content, names and places stay consistent across episodes. They’ve open-sourced the code and hosted a web version. If you’ve got old DVDs or obscure shows without subtitles, this is worth a look.

Host B: On the security side, researchers found a WordPress backdoor that rebuilds itself after cleanup. It’s called SC after markers in the injected code, and it uses multiple persistence mechanisms—files, database entries, and shared memory—so removing one doesn’t kill it. Sucuri’s calling it a “self-healing mesh.” If you’re running WordPress, this is a reminder to keep your plugins and themes updated, use a Web Application Firewall if you can, and have a solid backup strategy. Finally, Homarr v2 just shipped, and it’s a big release for homelab dashboards. We’ll dig into that next.

Host A: Homarr v2 just landed, and it’s a solid refresh for anyone running a homelab dashboard. The project describes itself as “the front door to your homelab,” and the new version backs that up with some real improvements. The two big features are Custom Widgets v2 and Workshop. Custom Widgets let you build almost any widget you want using JSX. You can write them yourself or describe what you want and generate it with an AI agent. The Workshop is a community marketplace where you can publish, vote on, and install widgets and custom CSS that other users have shared. [with a small lift] The team asks that people test their contributions before submitting, or the community will downvote them into oblivion—which is a nice way of keeping quality up.

Host B: The board editing system got a complete rebuild too. They switched to a drag-and-drop system based on dnd-kit, and it actually works now instead of being clunky. Containers replace the old Groups, and you get dynamic sections. Sidebars stay put while the board scrolls, which is a small thing but makes navigation feel better. The real architectural win is Integration Requests. Homarr connects to your services through integrations—Sonarr, Radarr, Prometheus, Docker, all of that. In v2, other features can reuse those connections without exposing the underlying credentials. So a Custom Widget can request data from Sonarr through Homarr. Homarr checks permissions, makes the request using stored credentials, and returns the result. The same system works over HTTP and optionally MCP, so you can give an MCP-compatible client like Claude Code access to selected Homarr capabilities without handing over API keys or direct network access to every service in your homelab.

Host A: They also added 31 new integrations in this release—Autobrr, Linkwarden, Prometheus, Frigate, Caddy, Mealie, and more. Docker and Podman support now handles multiple endpoints with assisted setup and docker labels. Performance improvements include parallel startup, on-demand loading for heavy screens, and request caching. The onboarding is completely reworked, so new users can get started faster. [thoughtful] One community member asked if they could use Claude Code to edit widgets instead of the built-in editor, and the answer is yes—you can instruct your AI agent to write custom widgets for you. Another operator mentioned they asked Claude Code to set up ntfy notifications and wire it into Sonarr, Radarr, Seerr, and other services without ever exposing API keys. That’s the kind of workflow that makes Homarr genuinely useful as a central control point.

Host B: The Homarr v2 release thread on r/homelab has been busy, and there’s some interesting discussion about dashboard preferences and migration paths. One operator mentioned they’ve been using Homepage for a long time and are ready to switch things up. The Homarr team pointed out they have an integration with Homepage docker labels, so if you’ve already got Homepage set up that way, the migration is pretty straightforward—no need to reconfigure everything from scratch. [lighter] Someone joked about repainting their front door tonight, which got a lot of upvotes. The demo site got hit hard with traffic and went down briefly, but the team scaled it up. A few people asked about specific use cases—one operator wanted to combine multiple script log files into a dashboard with tabs. The Homarr maintainers suggested building a small API server with Hono that returns logs as JSON, then using an AI agent to build a widget that calls that endpoint with tabs. That kind of flexibility is what makes Homarr stand out.

Host A: There’s also been discussion about the MCP integration. One person asked if they could have Claude Code edit widgets instead of using the built-in editor, and the answer is yes. Another operator shared that they used Claude Code to set up a notification provider and wire it into multiple services without ever needing to share API keys—Homarr handled the credential management and made the requests on their behalf. That’s a genuinely useful pattern for homelabbers who want to automate setup without managing secrets manually. The community seems genuinely excited about this release, and the team’s engagement in the thread is solid.

Host A: That’s Homelab Highlights for Friday. Until next time, happy hosting!