Skip to content
Tech News
← Back to articles

GitLab patches critical AI Gateway flaw allowing remote code execution

read original more articles
GoKawiil Brief

GitLab issued an advisory urging immediate patching of CVE-2026-90970, a critical vulnerability in its AI Gateway service that powers GitLab Duo. The flaw lets an authenticated user with Duo Agent Platform access escape a prompt template sandbox via a crafted flow configuration and run arbitrary commands on self-hosted AI Gateway instances. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the issue, noting GitLab-hosted AI Gateway customers are already protected.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The flaw highlights emerging risks in AI-integrated developer tools, where sandbox escapes could let attackers pivot from limited access to full command execution. GitLab's decision to privately notify self-hosted customers before public disclosure suggests the company treated exploitation risk as significant, though it has not disclosed whether the vulnerability was exploited. This follows a separate maximum-severity path traversal bug patched last month, pointing to a pattern of serious security issues surfacing in GitLab's platform.

Key Takeaways

Source: bleepingcomputer.com, 2026-10-02

Published there as: “GitLab warns of critical RCE vulnerability in AI Gateway service”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.