Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in GitLab AI Gateway (CVE‑2026‑90970) Threatens Self‑Hosted Deployments

GitLab patched CVE‑2026‑90970, a critical flaw that lets an authenticated Duo user escape the AI Gateway sandbox and run arbitrary commands. Organizations running self‑hosted gateways must patch immediately to retain audit‑ready control over application isolation.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Remote Code Execution in GitLab AI Gateway (CVE‑2026‑90970) Threatens Self‑Hosted Deployments

What It Is — GitLab disclosed a critical vulnerability (CVE‑2026‑90970) in its AI Gateway that allows an authenticated user with Duo Agent Platform access to break out of the prompt‑template sandbox and execute arbitrary commands on the host. The flaw scores 9.9 CVSS.

Exploitability — The vulnerability requires a valid Duo‑authenticated session and a crafted flow configuration; no public exploit code is known, but the high CVSS indicates a realistic risk for unpatched self‑hosted gateways.

Affected Products — GitLab AI Gateway versions 18.1.6‑19.2.3, 19.3.0‑19.3.1 (self‑hosted deployments). Cloud‑hosted GitLab.com, Dedicated, and managed gateways are already patched.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification that sandboxing and input‑validation controls remain effective after code changes.
  • Highlights the importance of maintaining up‑to‑date evidence of patch status for any self‑managed component that processes sensitive code or data.
  • Provides a concrete test of the “application security and isolation” control objective that underpins multiple frameworks (e.g., NIST AI RMF, ISO 42001).

Recommended Actions

  • Identify all self‑hosted GitLab AI Gateway instances and verify they run version 19.2.4 or later (or the corresponding 19.3.2/19.4.1 patches).
  • Update inventory and configuration‑management records to capture the patch as evidence of control remediation.
  • Review and harden prompt‑template handling logic; enforce least‑privilege permissions for Duo Agent users.
  • Enable logging of gateway command execution and monitor for anomalous activity.

Source: Security Affairs – CVE‑2026‑90970

📰 Original Source
https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →