importantSYS.SOURCE: The Hacker News• 2026-10-02T23:03:31+05:30
GitLab Addresses Critical AI Gateway Vulnerability (CVE-2026-90970) with Command Execution Risk for Self-Hosted Instances
GitLab has addressed a critical vulnerability (CVE-2026-90970) in its AI Gateway, rated 9.9/10 on CVSS, allowing command execution on self-hosted servers under specific conditions. Affected self-managed users must update to versions 19.2.4, 19.3.2, or 19.4.1, while GitLab-hosted customers are unaffected.
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.
The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The flaw
*** END OF TRANSMISSION ***