CVE-2026-90970: GitLab AI Gateway RCE
GitLab patched CVE-2026-90970, a critical authenticated RCE in the self-hosted AI Gateway for Duo users.
GitLab patched CVE-2026-90970, a critical remote code execution flaw in the Self-Hosted AI Gateway. An authenticated user who already has Duo Agent Platform access can execute arbitrary code on the gateway. The issue is a product vulnerability disclosure and patch, not a report of ongoing exploitation.
- CVE-2026-90970 is a critical RCE in GitLab's self-hosted AI Gateway.
- An authenticated user with Duo Agent Platform access can run arbitrary code.
- GitLab has released a patch; in-the-wild exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-909709.9<1%Prompt sandbox escape to RCE in GitLab AI Gatewaypublished · GitLab AI Gateway PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-90970 | Prompt sandbox escape to RCE in GitLab AI Gateway |
CVE-2026-90970: GitLab AI Gateway RCE GitLab has patched CVE-2026-90970 , a critical vulnerability in the Self-Hosted AI Gateway that can allow an authenticated user with Duo Agent Platform access to execute arbitrary co
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.