GitLab Warns of Critical RCE Vulnerability in AI Gateway Service
GitLab has issued an urgent alert regarding a critical remote code execution vulnerability impacting its AI Gateway service.
Urgent Alert: Critical Remote Code Execution Vulnerability in GitLab AI Gateway
Vulnerability Details
CVE-2026-90970 arises from a failure to properly neutralize input, enabling threat actors with limited privileges to execute arbitrary commands on affected systems. The AI Gateway serves as a conduit for AI-native features within GitLab Duo, with both cloud-hosted and self-managed deployment options available.
Impact and Exploitation
The vulnerability specifically affects instances utilizing the Duo Agent Platform, allowing authenticated users to bypass sandbox restrictions through manipulated flow configurations. This could result in full system compromise if left unaddressed.
GitLab’s Response
GitLab disclosed that versions 19.2.4, 19.3.2, and 19.4.1 include necessary fixes for self-hosted implementations. Customers relying on GitLab’s hosted AI Gateway service are automatically protected and do not require action. The company emphasized that targeted communication has been sent to self-hosted users ahead of the public disclosure, urging immediate upgrades to mitigate risks.
Related Vulnerabilities
This follows recent patches for other critical flaws, including a path traversal vulnerability (CVE-2026-85706) designated as actively exploited by U.S. cybersecurity authorities. CISA’s inclusion of CVE-2026-85706 in its list of actively exploited flaws under Binding Operational Directive 26-04 required federal agencies to implement fixes within three days.
Security Implications
Since 2021, five GitLab vulnerabilities have been linked to real-world exploitation, including instances involving ransomware operators. The AI Gateway vulnerability underscores ongoing challenges in securing AI-integrated development platforms. Organizations using self-managed deployments must prioritize applying the latest patches to prevent potential exploitation.
GitLab’s advisory highlights the importance of proactive security measures in environments combining AI capabilities with traditional DevSecOps workflows.
Conclusion
GitLab’s latest advisory reinforces the critical need for organizations to stay vigilant and apply security patches promptly, especially in AI-integrated systems where vulnerabilities can have far-reaching consequences.
