Ethical Hacking News
A critical vulnerability in GitLab's AI Gateway has been discovered, leaving organizations vulnerable to potential security breaches. The vulnerability, identified as CVE-2026-90970, affects the way the AI Gateway handles custom flow prompt templates and could potentially provide an attacker with a foothold inside the organization's infrastructure. GitLab has released patches for the affected AI Gateway releases, and organizations are urged to take immediate action to patch their installations and ensure the security of their AI infrastructure.
The tech world has been hit with a critical vulnerability in GitLab's AI Gateway, leaving organizations and users vulnerable to potential security breaches. The vulnerability, identified as CVE-2026-90970, affects the way the AI Gateway handles custom flow prompt templates. Authenticated users with access to the Duo Agent Platform can exploit the vulnerability to execute arbitrary commands on the AI Gateway host. The vulnerability does not require an unauthenticated connection, making it a significant security concern. GitLab has released patches for the affected AI Gateway releases and has credited the HackerOne researcher with responsibly reporting the vulnerability. Organizations running a GitLab Self-Hosted AI Gateway need to take immediate action to patch their installations. The discovery of this vulnerability highlights the importance of regular security audits and vulnerability testing.
The tech world has recently been hit with a critical vulnerability in GitLab's AI Gateway, leaving organizations and users vulnerable to potential security breaches. The vulnerability, identified as CVE-2026-90970, was discovered by HackerOne researcher invisiblemeerkat and has been fixed by GitLab.
The AI Gateway, which is a crucial component of GitLab's cloud-based services, sits between GitLab's AI features and the underlying models. It processes requests between the GitLab instance and the organization's AI infrastructure. The service also has access to sensitive authentication material, which makes it a significant target for attackers.
According to GitLab, the vulnerability affects the way the AI Gateway handles custom flow prompt templates. An authenticated user with access to the Duo Agent Platform could use a specially crafted flow configuration to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway host. This could potentially provide an attacker with a foothold inside the organization's infrastructure.
The vulnerability does not require an unauthenticated connection, and GitLab's advisory does not provide further details about the exact conditions required to exploit the flaw or the permissions needed beyond that access. This lack of information has left many questions unanswered, including the precise flow configuration needed to escape the template sandbox and the exact conditions under which the resulting command execution can be reached.
GitLab has credited the HackerOne researcher with responsibly reporting the vulnerability. The company has released patches for the affected AI Gateway releases, including versions 19.2.4, 19.3.2, and 19.4.1. Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance connected to a GitLab-hosted gateway do not need to take action, as the security fix has already been deployed to their hosted AI Gateways.
However, organizations that are running a GitLab Self-Hosted AI Gateway need to take immediate action to patch their installations. GitLab has already contacted these customers directly and strongly recommends updating affected installations immediately. The self-hosted deployment is designed for organizations that want to keep AI requests and responses inside their own environment. In such a configuration, the AI Gateway processes requests between the GitLab instance and the organization's AI infrastructure.
The implications of this vulnerability are significant, as it could potentially expose organizations to serious security breaches. Attackers could use the vulnerability to gain access to sensitive data and execute malicious commands on the AI Gateway host. The fact that the vulnerability does not require an unauthenticated connection makes it even more concerning, as it could potentially be exploited by attackers without needing to compromise the organization's network.
The discovery of this vulnerability highlights the importance of regular security audits and vulnerability testing. It also underscores the need for organizations to keep their AI Gateway installations up to date and to follow best practices for securing their AI infrastructure.
In conclusion, the critical vulnerability in GitLab's AI Gateway is a significant security concern that organizations need to take seriously. While GitLab has taken steps to fix the vulnerability, it is essential for organizations to take proactive measures to patch their installations and ensure the security of their AI infrastructure.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Vulnerability-in-GitLabs-AI-Gateway-Exposes-Organizations-to-Potential-Security-Breaches-ehn.shtml
https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html
Published: Sat Oct 3 07:56:16 2026 by llama3.2 3B Q4_K_M