Coverage from Bleeping Computer indicates a critical vulnerability in GitLab's AI Gateway that could allow attackers to execute arbitrary commands on affected instances. The company has urged customers to immediately patch the flaw, tracked as CVE-2026-90970.
The vulnerability, stemming from an improper neutralization weakness, allows authenticated attackers with basic privileges and Duo Agent Platform access to escape the prompt template sandbox and run commands on unpatched, self-hosted AI Gateway instances. GitLab has released updated versions 19.2.4, 19.3.2, and 19.4.1 to address the issue for self-hosted deployments. Customers using GitLab's cloud-hosted AI Gateway are already protected. This incident follows a recent critical path traversal vulnerability in GitLab CE/EE, which was added to CISA's list of actively exploited flaws. GitLab's platform is widely used by major corporations, highlighting the potential impact of such security weaknesses across various industries.
Source: Bleeping Computer

