CVE-2026-90970
CVSS 9.9 CRITICAL: gitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway…
Vulnerabilità ed exploit
GitLab ha corretto CVE-2026-90970, una RCE critica nell’AI Gateway che riguarda solo chi ospita in proprio quel componente. GitLab ha già sistemato i gateway gestiti da sé, quindi il perimetro a rischio si restringe agli operatori self-hosted e alle installazioni rimaste indietro.
Un utente già autenticato con accesso a Duo Agent Platform può, in certe condizioni, far uscire un custom flow dal suo prompt template sandbox e trasformarlo in comandi eseguiti sul gateway. In pratica, il ponte fidato tra GitLab e i modelli AI diventa un punto da cui l’attaccante può prendere il controllo della macchina che instrada le richieste.
La correzione è nelle versioni 19.2.4, 19.3.2 e 19.4.1 dell’AI Gateway, distribuito come Docker image o Helm chart separati. Per chi usa un gateway self-hosted, il rischio resta confinato a quel layer: GitLab applicato alla piattaforma principale non basta se il gateway è rimasto fermo a una release vulnerabile.
2 fonti · 5 ore fa
CVSS 9.9 CRITICAL: gitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway…
The Hacker News
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab fixed CVE-2026-90970, a 9.9 AI Gateway flaw that could let logged-in Duo Agent Platform users run commands on self-hosted gateways.
originaleBleepingComputer
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
originalePart of the PlainSec briefing for 2026-10-02
Every edition of this story: Il ponte AI di GitLab espone solo chi lo ospita