chiprook
← Security
SecurityOctober 2, 2026, 23:20

GitLab warns of critical RCE flaw in AI Gateway service

GitLab disclosed a critical AI Gateway vulnerability, CVE-2026-90970, that lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands. Fixes are available in versions 19.2.4, 19.3.2 and 19.4.1 for Self-Hosted AI Gateway; GitLab-hosted instances are already protected.

GitLab warns of critical RCE flaw in AI Gateway service
#GitLab
Read next
Security

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Security

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

Security

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials

Security

SolarWinds Patches Two Critical RCE Flaws in Observability Self-Hosted