vulnerability
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
HighCVSS 9.9
Summary
A critical vulnerability (CVE-2026-90970) in GitLab's AI Gateway allows a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateways. Self-managed users should immediately update their gateways.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
