GitLab patches AI Gateway flaw CVE-2026-90970 that could allow remote code execution

First reported by Security Affairs at · Updated · 2 sources

The vulnerability has a CVSS score of 9.9 and affects self-hosted AI Gateway deployments supporting GitLab Duo features. Authenticated attackers could execute commands remotely. According to Security Affairs, users with access to the Duo Agent Platform could escape a prompt sandbox and run commands on the gateway.

  • Cyber Security News lists patched AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.

Covered by 2 publishers within 7 hours of the first report.

Reporting2

Security Affairs CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed · Pierluigi Paganini