← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 3, 2026 · 04:11via Cyber Security News

Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

Brief

GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9. 9 and affects self-hosted deployments used to support GitLab Duo AI features.

The company released AI Gateway versions 19.

  • 4, 19.
  • 2, and 19.
  • 1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early guidance on the required updates.

GitLab AI Gateway Vulnerability

The vulnerability involves improper handling of custom flow prompt templates.

Read more on Cyber Security News→