hacker-news · Crawled Oct 2, 2026
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Read original article ↗AI Summary
GitLab has patched a critical vulnerability, CVE-2026-90970, in its self-hosted AI Gateway that could allow a logged-in user with access to the Duo Agent Platform to execute arbitrary commands on the gateway via a crafted custom flow configuration. The flaw, rated 9.9 on the CVSS scale, stems from a prompt template sandbox escape in the AI Gateway's custom flow feature. Organizations hosting their own AI Gateway instances are advised to update immediately to fixed versions 19.2.4, 19.3.2, or 19.4.1, as no workaround is available and exploitation could lead to command execution on the underlying system.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.