#92 · Briefing ·

GitLab Patches Critical AI Gateway Flaw

GitLab has released critical security patches for its AI Gateway to address a vulnerability that could allow authenticated users to execute unauthorized commands.

Patch Self-Hosted AI Gateway Immediately
AI-generated illustration. Patch Self-Hosted AI Gateway Immediately

GitLab has deployed critical security updates to address a severe vulnerability in its AI Gateway, tracked as CVE-2026-90970. The release of these patches aims to prevent unauthorized command execution on affected systems, specifically targeting self-hosted environments. To resolve the issue, GitLab has rolled out updates across several versions of the gateway, ensuring that the underlying flaw is neutralized for users who apply the fixes.

According to GitLab, the vulnerability allows an authenticated user with Duo Agent Platform access to bypass the prompt template sandbox and execute arbitrary commands under certain conditions. The security researcher invisiblemeerkat responsibly disclosed this vulnerability to GitLab via the HackerOne bug bounty platform. Before releasing the public security advisory, GitLab proactively conducted targeted outreach to customers operating self-hosted gateways to warn them of the security risk.

This security update matters because only organizations hosting their own AI Gateway must manually apply the patches to secure their environments. GitLab has already patched its own hosted gateways, which automatically protects customers on GitLab.com, GitLab Dedicated, and connected self-managed instances without requiring administrative action on their part. The vulnerability is resolved in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.

Regarding external assessments, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has analyzed the threat landscape for this vulnerability. CISA currently lists the active exploitation status of CVE-2026-90970 as none, indicating there is no public evidence of malicious actors leveraging this specific loophole.

Despite the release of the patches, several details remain unknown. The official advisory does not describe the specific conditions needed to trigger the sandbox escape, nor does it name any specific user roles beyond general Duo Agent Platform access. Furthermore, there is no provided workaround for self-hosted gateways that cannot be immediately updated, and GitLab has not provided a method for administrators to check if a gateway was compromised prior to applying the update.

Sources

Verified claims

Stills

Second 9.9 Flaw This Year
Second 9.9 Flaw This Year
What is still unknown
AI-generated. What is still unknown

Original reporting: https://thehackernews.com/2026/10/gitlab-patches-critical-99-ai-gateway.html?m=1

Written by The Quiet Search. Method: /about.

Related

Comments

Plain text only. New comments stay hidden until a person reviews them.