Critical GitLab AI Gateway Flaw Allows Remote Code Execution
Want more insights like this?
GitLab has pushed urgent security updates to fix a critical vulnerability in its AI Gateway component, tracked as CVE-2026-90970 with a near-perfect CVSS 3.1 score of 9.9. The flaw lets authenticated users with Duo Agent Platform access submit crafted flow configurations that break out of the prompt template sandbox and execute arbitrary commands on the gateway server. Security researcher invisiblemeerkat reported it.
Affected builds run from 18.1.6 up to 19.2.4, plus 19.3 before 19.3.2 and 19.4 before 19.4.1 — and those three releases are the fixes, available now. Note that's the gateway's own version, not your GitLab instance's, so check the deployment itself before deciding you're clear.
Most customers don't have to. GitLab.com, Dedicated, and self-managed instances pointed at a GitLab-hosted gateway are already covered. Only operators running their own AI Gateway must upgrade manually — immediately. GitLab hasn't reported any exploitation, but the attack needs low complexity and no user interaction at all, so the bar is a valid Duo-enabled account and nothing more.
Source: Cybersecurity News