GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab urges immediate patches for critical AI Gateway RCE CVE-2026-90970 on self-hosted instances.
GitLab warned that CVE-2026-90970, an improper neutralization flaw in the AI Gateway, lets an authenticated user with Duo Agent Platform access escape the prompt-template sandbox through a crafted flow configuration and run arbitrary commands. Fixes are in versions 19.2.4, 19.3.2, and 19.4.1 for self-hosted gateways; GitLab-hosted gateways are already protected. The report also notes last month's unauthenticated path traversal CVE-2026-85706 in GitLab CE and EE, which CISA added to its exploited-vulnerability catalog under BOD 26-04.
- CVE-2026-90970 allows authenticated command execution on the AI Gateway
- Self-hosted installs should move to 19.2.4, 19.3.2, or 19.4.1
- GitLab-hosted AI Gateway customers are already protected
- CISA lists path traversal CVE-2026-85706 as actively exploited
- GitLab cites over 30 million users and broad Fortune 100 use
Vulnerabilities mentionedAll →
- CVE-2026-8570610.093%Unauthenticated Path Traversal Arbitrary File Read in GitLab CE/EEpublished · GitLab Community Edition KEV PoC ×13
Full article439 words · extracted from bleepingcomputer.com · click to collapse

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instances on GitLab Self-Managed through GitLab Duo Self-Hosted.
Tracked as CVE-2026-90970, this security flaw stems from an improper neutralization weakness and can let attackers with basic privileges and Duo Agent Platform access execute arbitrary commands on unpatched instances.
"GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway," the company explained in a Friday advisory.
GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address this vulnerability for Self-Hosted AI Gateway users and said that customers using a GitLab-hosted AI Gateway are already protected and do not need to take action.
"These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately," it said. "We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance."
GitLab added that it reached out to those who host their own AI Gateway before disclosure and urged users to upgrade vulnerable instances as soon as possible.
Last month, GitLab also patched a maximum severity path traversal vulnerability (CVE-2026-85706) in GitLab Community Edition (CE) and Enterprise Edition (EE) that allows unauthenticated attackers to read sensitive data such as credentials and other secrets from vulnerable servers.
One day later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its list of actively exploited flaws and gave federal agencies three days to secure their systems as mandated by Binding Operational Directive (BOD) 26-04.
Since November 2021, CISA has tagged five GitLab vulnerabilities abused in the wild, including one exploited by ransomware gangs.
GitLab's DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.