GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
AI-summarised brief · reviewed before publication
GitLab disclosed a critical vulnerability (CVE‑2026‑90970) in its AI Gateway that could allow a logged‑in user with Duo Agent Platform access to execute arbitrary commands on self‑hosted gateways under specific conditions. The flaw, rated 9.9/10, affects gateway versions 18.1.6 through 19.1 and is fixed in 19.2.4, 19.3.2, and 19.4.1. GitLab urged immediate updates for self‑managed customers, while GitLab.com, Dedicated, and hosted‑gateway users are unaffected. The issue stems from a prompt‑template escape in custom flows.
💡 Why It Matters
- · The flaw exposes a critical entry point for attackers to compromise AI‑integrated infrastructure, underscoring the urgent need for robust security controls in emerging AI workflows.