Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

GitLab fixes critical RCE flaw in AI Gateway

GitLab has released security updates for a critical remote code execution vulnerability in its AI Gateway service. The flaw could let an authenticated user with Duo Agent Platform access run arbitrary commands on an unpatched instance under certain conditions.

Tracked as CVE-2026-90970, the vulnerability stems from improper neutralization. GitLab said a specially crafted flow configuration could let a user escape the prompt template sandbox and execute commands on the AI Gateway.

GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the issue for customers running Self-Hosted AI Gateway. The company urged GitLab Self-Managed customers with those installations to update immediately. Customers using GitLab-hosted AI Gateway are already protected and do not need to take action, GitLab said.

GitLab said it contacted Self-Hosted AI Gateway customers before publishing its advisory. The service provides access to AI-native GitLab Duo features. GitLab operates a cloud-based gateway for GitLab.com, GitLab Self-Managed, and GitLab Dedicated; customers can also deploy their own gateway through GitLab Duo Self-Hosted.

Last month, GitLab also patched CVE-2026-85706, a maximum-severity path traversal flaw in Community Edition and Enterprise Edition that could let unauthenticated attackers read sensitive data, including credentials and other secrets. CISA added that vulnerability to its actively exploited list one day later and gave federal agencies three days to secure their systems.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.