CVE-2026-90970
CVSS 9.9 CRITICAL: gitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway…
Vulnerabilities · 4h ago
GitLab fixed CVE-2026-90970 in its AI Gateway on October 2, a critical remote command execution flaw that affects self-hosted gateway operators. GitLab said its hosted gateways were already fixed centrally, so the exposed population is the smaller set running the gateway themselves.
The bug sits in the AI bridge, not the main GitLab app: a logged-in Duo Agent Platform user can send a request that the gateway accepts as valid and, under certain conditions, turns into commands on the gateway host. In plain terms, the trusted service that relays AI traffic becomes a command slot, so compromise lands on the gateway machine and the AI request path it fronts.
That boundary matters for cleanup and risk. If a team runs its own gateway as a Docker or Helm deployment, patch status on GitLab proper does not tell the whole story; the separate gateway release does. For organizations that keep AI traffic inside their own environment, the exposure stays with whoever still owns that self-hosted component.
CVSS 9.9 CRITICAL: gitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway…
2 sources covering this story
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab fixed CVE-2026-90970, a 9.9 AI Gateway flaw that could let logged-in Duo Agent Platform users run commands on self-hosted gateways.
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
Part of the PlainSec briefing for 2026-10-02