Skip to content
Critical GitLab AI Gateway Vulnerability Allows Command Execution

Critical GitLab AI Gateway Vulnerability Allows Command Execution

First seen 4 Oct 2026, 17:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 18:02 UTC
  • •CVE-2026-90970 is a critical vulnerability with a CVSS score of 9.9.
  • •Authenticated users can exploit the vulnerability to execute arbitrary commands on the host.
  • •GitLab has released patches and recommends immediate upgrades for affected self-hosted deployments.

On October 2, 2026, GitLab disclosed a critical vulnerability (CVE-2026-90970) in its AI Gateway component, affecting self-hosted deployments with Duo AI features. The vulnerability, which has a CVSS score of 9.9, allows authenticated users with low privileges to execute arbitrary commands on the host by escaping a template sandbox via specially crafted flow configurations. GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1, urging affected customers to upgrade immediately. There is currently no evidence of exploitation in the wild or public proof-of-concept code. The vulnerability is classified as CWE-1336, indicating improper neutralization of special elements in a template engine. Detection of potential exploitation involves monitoring unusual modifications to custom flows and unexpected process activity on the AI Gateway host.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
CVE-2026-90970 published
GitLab disclosed a critical vulnerability in the AI Gateway affecting self-hosted deployments.
Rescana
2026-10-03
First public PoC released
Public proof-of-concept code for CVE-2026-90970 was made available.
KNOWN CVE DATES
2026-10-03
GitLab releases patches
GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the vulnerability.
X

More articles in this cluster (4)

Following this threat?

Track CVE-2026-90970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of GitLab are affected?
The vulnerability affects self-hosted deployments of GitLab AI Gateway that support Duo AI features.
Is there any evidence of exploitation?
As of October 3, 2026, there is no evidence of exploitation in the wild or public proof-of-concept code.
What should I do if I'm affected?
Upgrade to GitLab AI Gateway versions 19.2.4, 19.3.2, or 19.4.1 immediately to mitigate the risk.