GitLab patches critical AI Gateway flaw CVE-2026-90970
GitLab fixed CVE-2026-90970, a CVSS 9.9 authenticated command-execution bug in self-hosted AI Gateway builds from 18.1.6 before 19.2.4, 19.3.2, and 19.4.1.
GitLab fixed CVE-2026-90970, a CWE-1336 improper-neutralization flaw in its AI Gateway that lets an authenticated user with Duo Agent Platform access escape a custom-flow prompt-template sandbox through a crafted flow configuration and execute arbitrary commands on the gateway. The Hacker News and Cyber Security News report a CVSS score of 9.9; BleepingComputer describes the flaw as critical without stating a score, so the sources do not conflict on the core bug. Cyber Security News says affected builds start at 18.1.6 and run through releases before the fixes in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1. Only organizations running self-hosted gateways must patch; GitLab-hosted gateway, GitLab.com, and GitLab Dedicated customers are already protected. The Hacker News says CISA's assessment lists exploitation as none with no public proof of concept, and Cyber Security News likewise reports no public exploit or active exploitation; the issue is the same template-engine class as February's CVE-2026-1868. On October 2, 2026, Canada's Cyber Centre issued advisory AV26-994 urging administrators to apply updates without naming a CVE, while BleepingComputer separately notes that path-traversal CVE-2026-85706 was added to CISA's exploited-vulnerability catalog under BOD 26-04.
- CVE-2026-90970 is a CWE-1336 improper-neutralization flaw in GitLab's AI Gateway; The Hacker News and Cyber Security News score it CVSS 9.9, while BleepingComputer calls it critical without a score.
- An authenticated user with Duo Agent Platform access can escape a custom-flow prompt-template sandbox with a crafted flow configuration and run arbitrary commands on the gateway.
- Cyber Security News says affected self-hosted builds start at 18.1.6 and continue through releases before the fixes in 19.2.4, 19.3.2, and 19.4.1.
- Only self-hosted AI Gateway operators must patch; GitLab-hosted gateways, GitLab.com, and GitLab Dedicated are already protected.
- The Hacker News says CISA lists exploitation as none with no public proof of concept; Cyber Security News likewise reports no public exploit or active exploitation.
- The bug is the same template-engine class as February's CVE-2026-1868.
- On October 2, 2026, the Canadian Centre for Cyber Security issued advisory AV26-994 urging updates, without naming a CVE or exploitation details.
- Separately, BleepingComputer notes unauthenticated path-traversal CVE-2026-85706 in GitLab CE and EE was added to CISA's exploited-vulnerability catalog under BOD 26-04, and that GitLab cites more than 30 million users and broad Fortune…
Coverage timelineoldest first · each row is one article
- · 12h agoGitLab warns of critical RCE vulnerability in AI Gateway service
BleepingComputer· 76
GitLab urges immediate patches for critical AI Gateway RCE CVE-2026-90970 on self-hosted instances.
- · 10h agoGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
The Hacker News· 64
GitLab patched CVE-2026-90970, a CVSS 9.9 command-execution flaw in self-hosted AI Gateway.
- · 10h agoGitLab security advisory (AV26-994)
Canadian Centre for Cyber Security· 20
Canadian Cyber Centre advisory urges administrators to patch GitLab AI Gateway flaws fixed in versions 19.2.4, 19.3.2, and 19.4.1.
Vulnerabilities in this storyAll →
- CVE-2026-18689.9<1%GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6…published
- CVE-2026-8570610.093%Unauthenticated Path Traversal Arbitrary File Read in GitLab CE/EE