Vulnerabilities · 4h ago

GitLab AI Gateway RCE Hits Self-Hosted Operators

GitLab fixed CVE-2026-90970 in its AI Gateway on October 2, a critical remote command execution flaw that affects self-hosted gateway operators. GitLab said its hosted gateways were already fixed centrally, so the exposed population is the smaller set running the gateway themselves.

The bug sits in the AI bridge, not the main GitLab app: a logged-in Duo Agent Platform user can send a request that the gateway accepts as valid and, under certain conditions, turns into commands on the gateway host. In plain terms, the trusted service that relays AI traffic becomes a command slot, so compromise lands on the gateway machine and the AI request path it fronts.

That boundary matters for cleanup and risk. If a team runs its own gateway as a Docker or Helm deployment, patch status on GitLab proper does not tell the whole story; the separate gateway release does. For organizations that keep AI traffic inside their own environment, the exposure stays with whoever still owns that self-hosted component.

CVE-2026-90970

NVD KEV

CVSS 9.9 CRITICAL: gitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway…

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-02

Editions

Related stories