BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GitLab AI Gateway critical flaw enables remote code execution

A critical GitLab AI Gateway flaw (CVE-2026-90970) allows command execution; update immediately to fixed versions.

  • GitLab disclosed a critical vulnerability, CVE-2026-90970, in its AI Gateway with a CVSS score of 9.9.
  • The flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on the gateway.
  • Fixes are available in gateway versions 19.2.4, 19.3.2, and 19.4.1; GitLab strongly recommends self-hosted gateway users update immediately.

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory on October 2. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act.

- Advertisement -

The flaw is tracked as CVE-2026-90970 and was rated critical with a CVSS score of 9.9 out of 10. GitLab runs AI Gateways for its customers and has already fixed them, meaning customers on GitLab.com, GitLab Dedicated, and self-managed instances using a GitLab-hosted gateway do not need to act.

Self-managed customers who host their own gateway are advised to update immediately. The advisory does not say whether the flaw has been used in attacks, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed exploitation as “none.”

The vulnerability is in the prompt template of a custom flow on the Duo Agent Platform. A logged-in user with access could “escape the prompt template sandbox via a specially crafted flow configuration,” leading to arbitrary command execution on the gateway.

GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw. In February, GitLab fixed another gateway flaw, CVE-2026-1868, which also had a 9.9 rating and was a template engine weakness of the same class, CWE-1336.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Lloyds: 3 in 4 UK Banks Eye Tokenization Shift

Nearly 75% of major UK financial institutions expect tokenization to reshape financial services, according...

Bitcoin Reaches $86.8K as Inflation Reading Raises Rate Pause Odds

Bitcoin traded at $86,757 Friday, up 3% on the day and 2% over the...

Nike stock crashes to 13-year low amid layoffs

Nike's stock fell to a 13-year low as revenue slipped 4% and the company...

Ammous: Bitcoin treasury firms can’t match Saylor’s Strategy

Strategy's large Bitcoin holdings and cash reserves give it lower borrowing costs and resilience...

Android 17 Blocks Malware via Accessibility Service Lockdown

Google restricts Android’s accessibility services to verified apps when Advanced Protection is enabled, closing...

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading