GitLab patches critical AI Gateway RCE and tells self-hosted users to upgrade
Hosted customers are already covered, while self-managed deployments need an immediate update to stop command execution.
GitLab has disclosed a critical remote command‑execution bug in its AI Gateway service, tracked as CVE-2026-90970, that allows authenticated users with Duo Agent Platform access to run arbitrary commands on vulnerable instances. The issue comes from improper input handling that lets a user break out of the prompt-template sandbox using a crafted flow configuration. GitLab has already fixed its own hosted AI Gateway environment, but self‑managed customers running GitLab Self-Hosted AI Gateway must upgrade immediately to versions 19.2.4, 19.3.2, or 19.4.1. The company says it has directly notified affected self‑hosted AI Gateway users in advance of this public advisory. This follows a separate maximum‑severity GitLab path traversal flaw (CVE-2026-85706) patched last month that CISA has confirmed is being actively exploited, underscoring the need for fast patching of GitLab deployments.
Why it matters
The risk is limited to self-hosted AI Gateway users, but for them the bug can let an authenticated user with Duo Agent Platform access run arbitrary commands on vulnerable instances. GitLab has already shipped fixed versions and warned affected customers in advance, so the practical change is that exposed deployments need to move now rather than wait for the issue to spread further.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer