chiprook
← Security
SecurityOctober 5, 2026, 15:29

GitLab Patches CVSS 9.9 RCE in Its AI Gateway

On October 2, 2026, GitLab disclosed CVE-2026-90970 (CVSS 9.9) in its AI Gateway: an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox and run arbitrary commands. Fixes shipped in versions 19.2.4, 19.3.2 and 19.4.1; GitLab-hosted gateways are patched, self-hosted ones are not.

GitLab Patches CVSS 9.9 RCE in Its AI Gateway
#GitLab
Read next
Security

GitLab warns of critical RCE flaw in AI Gateway service

Security

GitLab patches 11 flaws, including two 9.9-rated RCEs

Security

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch

Security

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials