GitLab has fixed a critical AI Gateway flaw, tracked as CVE-2026-90970, that could let a logged-in user with Duo Agent Platform access execute arbitrary commands under certain conditions. Organizations hosting their own gateway should update immediately to the patched versions 19.2.4, 19.3.2, or 19.4.1. #GitLab #CVE-2026-90970 #DuoAgentPlatform
Keypoints
- The flaw affects GitLabβs self-hosted AI Gateway.
- A logged-in user with Duo Agent Platform access could trigger command execution.
- The issue is tracked as CVE-2026-90970 and rated critical with a CVSS score of 9.9.
- Fixed versions are 19.2.4, 19.3.2, and 19.4.1.
- GitLab.com, GitLab Dedicated, and GitLab-hosted gateway users do not need to act.
Read More: https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html