News Security

GitLab fixes critical AI Gateway flaw enabling arbitrary command execution

GitLab AI Gateway vulnerability CVE-2026-90970

GitLab has fixed a critical vulnerability in its AI Gateway service that could allow an authenticated user with basic privileges and Duo Agent Platform access to execute arbitrary commands on an unpatched instance. Tracked as CVE-2026-90970, the issue affects self-hosted AI Gateway deployments under specific conditions.

The vulnerability involves improper neutralization of input. A specially crafted flow configuration could allow an authenticated user to escape the prompt template sandbox used by the AI Gateway, leading to command execution on the service. The available evidence describes the potential impact, but does not establish that CVE-2026-90970 has been exploited in the wild.

Affected and fixed versions

GitLab’s vulnerability record identifies affected AI Gateway versions as:

  • 18.1.6 through versions before 19.2.4
  • 19.3 before 19.3.2
  • 19.4 before 19.4.1

GitLab addressed the issue in versions 19.2.4, 19.3.2, and 19.4.1. These fixes apply to customers running their own AI Gateway through GitLab Self-Managed and GitLab Duo Self-Hosted.

Customers using GitLab’s hosted AI Gateway on GitLab.com or GitLab Dedicated are described as already protected and do not need to take action for this issue. Organizations running a self-hosted instance should identify the deployed AI Gateway version and upgrade to one of the fixed releases as soon as possible. GitLab said it had contacted self-hosted AI Gateway customers before the public advisory.

Why it matters

AI Gateway provides access to AI-native GitLab Duo features, so it may sit within development environments that can reach internal services or sensitive project resources. The issue is limited by the requirement for authentication, relevant privileges, and Duo Agent Platform access, but successful command execution on the gateway could still expand the consequences of a compromised or misused account.

The evidence does not provide additional indicators of compromise, log locations, or temporary mitigations. Administrators should therefore focus on confirming whether they operate a self-hosted AI Gateway and checking that it runs 19.2.4, 19.3.2, 19.4.1, or a later release where applicable.

GitLab’s AI Gateway installation documentation and patch release notice provide the relevant deployment and release context. BleepingComputer’s report contains additional coverage of the advisory.

Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!

Discover more from ToolsLib Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading

×