Skip to content
GitLab Issues Urgent Patch for Critical AI Gateway RCE Flaw

GitLab Issues Urgent Patch for Critical AI Gateway RCE Flaw

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-90970 is a critical RCE vulnerability with a CVSS score of 9.9.
  • •The flaw allows authenticated users to execute arbitrary commands on self-hosted AI Gateways.
  • •Patches are available in versions 19.2.4, 19.3.2, and 19.4.1; immediate updates are recommended.

GitLab has disclosed a critical remote code execution vulnerability, CVE-2026-90970, affecting self-hosted AI Gateways. The flaw allows authenticated users with Duo Agent Platform access to escape a prompt template sandbox and execute arbitrary commands on the gateway. GitLab released patches in versions 19.2.4, 19.3.2, and 19.4.1 on October 2, 2026, and strongly recommends that self-managed customers update immediately. The vulnerability has a CVSS score of 9.9, indicating a high severity level. Customers using GitLab's hosted AI Gateway are not affected and do not need to take action. GitLab has contacted affected customers with guidance prior to the public advisory. The flaw was reported by a researcher on HackerOne, and the first public proof of concept was released on October 3, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-02-09
CVE-2026-1868 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-11
CVE-2026-85706 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-10-02
CVE-2026-90970 disclosed
GitLab announced a critical RCE vulnerability affecting self-hosted AI Gateways, urging immediate updates.
Thehackernews
2026-10-02
Patches released
GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the critical flaw.
docs.gitlab.com
2026-10-03
First public PoC released
A proof of concept for CVE-2026-90970 was made public, demonstrating the vulnerability.
Sqmagazine

More articles in this cluster (4)

Following this threat?

Track CVE-2026-1868 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who is affected by CVE-2026-90970?
Only customers running self-hosted AI Gateways are affected and need to update.
What should I do if I'm using a self-hosted AI Gateway?
Immediately update to one of the patched versions: 19.2.4, 19.3.2, or 19.4.1.
Is there any evidence of exploitation in the wild?
The advisory does not confirm any exploitation in the wild, but a public PoC has been released.