GitLab has warned customers to urgently patch CVE-2026-90970, a critical AI Gateway vulnerability that could let authenticated attackers with basic privileges escape the sandbox and execute arbitrary commands on vulnerable self-hosted instances. The company released fixed versions for GitLab Self-Hosted AI Gateway users and said hosted GitLab AI Gateway customers are already protected, following its recent patching of CVE-2026-85706. #GitLab #CVE-2026-90970 #CVE-2026-85706 #CISA
Keypoints
- GitLab says CVE-2026-90970 can lead to arbitrary command execution on AI Gateway.
- The flaw affects GitLab Self-Hosted AI Gateway deployments.
- Attackers need basic privileges and Duo Agent Platform access to abuse it.
- GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the issue.
- GitLab also recently patched CVE-2026-85706, a path traversal flaw added to CISAβs actively exploited list.