www.penligent.ai Critical GitLab AI Gateway Vulnerability Allows Command Execution
Article Content
- •CVE-2026-90970 is a critical vulnerability with a CVSS score of 9.9.
- •Authenticated users can exploit the vulnerability to execute arbitrary commands on the host.
- •GitLab has released patches and recommends immediate upgrades for affected self-hosted deployments.
On October 2, 2026, GitLab disclosed a critical vulnerability (CVE-2026-90970) in its AI Gateway component, affecting self-hosted deployments with Duo AI features. The vulnerability, which has a CVSS score of 9.9, allows authenticated users with low privileges to execute arbitrary commands on the host by escaping a template sandbox via specially crafted flow configurations. GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1, urging affected customers to upgrade immediately. There is currently no evidence of exploitation in the wild or public proof-of-concept code. The vulnerability is classified as CWE-1336, indicating improper neutralization of special elements in a template engine. Detection of potential exploitation involves monitoring unusual modifications to custom flows and unexpected process activity on the AI Gateway host.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-90970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of GitLab are affected?
Is there any evidence of exploitation?
What should I do if I'm affected?
Continue Reading
GitLab Issues Urgent Patch for Critical AI Gateway RCE Flaw GitLab has disclosed a critical remote code execution vulnerability, CVE-2026-90970, affecting self-hosted AI Gateways. The flaw allows authenticated users with Duo Agent Platform access to escape a prompt template sandbox and execute arbitrary commands on the gateway. GitLab released patches in versions 19.2.4…
Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint GitLab and Dell released critical patches for remote code execution vulnerabilities on October 3, 2026. GitLab's AI Gateway vulnerability (CVE-2026-90970) allows arbitrary command execution on self-hosted instances, with a CVSS score of 9.9. Dell's Container Storage Modules have critical flaws (CVSS 10.0) enabling…