Tech News
← Home  ·  All topics

Duo Agent Platform

1 GoKawiil brief on this topic

GitLab patches critical AI Gateway flaw allowing remote code execution

GitLab issued an advisory urging immediate patching of CVE-2026-90970, a critical vulnerability in its AI Gateway service that powers GitLab Duo. The flaw lets an authenticated user with Duo Agent Platform access escape a prompt template sandbox via a crafted flow configuration and run arbitrary commands on self-hosted AI Gateway instances. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the issue, noting GitLab-hosted AI Gateway customers are already protected.