Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
GitLab patched CVE-2026-90970, a CVSS 9.9 flaw letting authenticated Duo users execute commands on self-hosted AI Gateways.
GitLab patched CVE-2026-90970, a CVSS 9.9 flaw in self-hosted AI Gateway deployments used for GitLab Duo. An authenticated user with Duo Agent Platform access can submit a crafted flow configuration that escapes the prompt-template sandbox and executes arbitrary commands on the gateway. Affected builds start at 18.1.6 and run through releases before 19.2.4, 19.3.2, and 19.4.1. GitLab-hosted gateways are already fixed, and the advisory reports neither a public exploit nor active exploitation.