news.mlab.sh
Back to the feed
vulnerability

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

HighCVSS 9.9
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-90970) in GitLab's AI Gateway allows a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateways. Self-managed users should immediately update their gateways.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Also covered by 1 other source(s)

Report an error
Confirmed errors are fixed and listed on /corrections.