GitLab patches critical AI Gateway flaw allowing remote code execution
GitLab issued an advisory urging immediate patching of CVE-2026-90970, a critical vulnerability in its AI Gateway service that powers GitLab Duo. The flaw lets an authenticated user with Duo Agent Platform access escape a prompt template sandbox via a crafted flow configuration and run arbitrary commands on self-hosted AI Gateway instances. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the issue, noting GitLab-hosted AI Gateway customers are already protected.
GoKawiil's interpretation of the reporting above, not reported fact.
The flaw highlights emerging risks in AI-integrated developer tools, where sandbox escapes could let attackers pivot from limited access to full command execution. GitLab's decision to privately notify self-hosted customers before public disclosure suggests the company treated exploitation risk as significant, though it has not disclosed whether the vulnerability was exploited. This follows a separate maximum-severity path traversal bug patched last month, pointing to a pattern of serious security issues surfacing in GitLab's platform.
- CVE-2026-90970 allows authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted AI Gateway instances.
- GitLab released fixed versions 19.2.4, 19.3.2, and 19.4.1 and urges immediate upgrades for self-managed deployments.
- GitLab-hosted AI Gateway customers on GitLab.com, Self-Managed, and Dedicated are already protected and need no action.
Source: bleepingcomputer.com, 2026-10-02
Published there as: “GitLab warns of critical RCE vulnerability in AI Gateway service”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.