bleeping-computer · Crawled Oct 2, 2026

GitLab warns of critical RCE vulnerability in AI Gateway service

Read original article ↗

AI Summary

GitLab has disclosed a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-90970, in its AI Gateway service that affects self-hosted instances. The flaw stems from improper neutralization, allowing authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands. GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1 for Self-Hosted AI Gateway users, urging immediate updates. Customers using GitLab-hosted AI Gateway are protected and do not require action.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.