GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
thehackernews.com Oct 2, 2026

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

AI-summarised brief · reviewed before publication

GitLab disclosed a critical vulnerability (CVE‑2026‑90970) in its AI Gateway that could allow a logged‑in user with Duo Agent Platform access to execute arbitrary commands on self‑hosted gateways under specific conditions. The flaw, rated 9.9/10, affects gateway versions 18.1.6 through 19.1 and is fixed in 19.2.4, 19.3.2, and 19.4.1. GitLab urged immediate updates for self‑managed customers, while GitLab.com, Dedicated, and hosted‑gateway users are unaffected. The issue stems from a prompt‑template escape in custom flows.

💡 Why It Matters

  • · The flaw exposes a critical entry point for attackers to compromise AI‑integrated infrastructure, underscoring the urgent need for robust security controls in emerging AI workflows.