chiprook
← Security
SecurityOctober 9, 2026, 13:13

GitLab patches CVSS 9.9 CVE-2026-90970 in AI Gateway

On October 2 GitLab disclosed CVE-2026-90970, a CVSS 9.9 sandbox escape in AI Gateway prompt templates that lets an authenticated Duo Agent Platform user run arbitrary commands. Fixed in 19.2.4, 19.3.2 and 19.4.1; only self-hosted gateways are affected.

GitLab patches CVSS 9.9 CVE-2026-90970 in AI Gateway
#GitLab
Read next
Security

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials

Security

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)

Security

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch

Security

GitLab patches 11 flaws, including two 9.9-rated RCEs