Ethical Hacking News
GitLab has discovered a critical flaw in its AI Gateway that could allow an attacker to run commands on the gateway without permission. The vulnerability, rated critical with a CVSS score of 9.9, has been fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. Customers with self-hosted gateways are advised to update immediately to mitigate the risk.
A recent vulnerability (CVE-2026-90970) has been discovered in GitLab's AI Gateway, rated critical with a CVSS score of 9.9. The vulnerability allows a logged-in user with Duo Agent Platform access to run commands on the gateway under certain conditions. The AI Gateway holds sensitive credentials and presents a security risk, despite providing control over AI request and response data. The vulnerability lies in a custom flow's prompt template and can lead to arbitrary command execution on the gateway. GitLab credits a HackerOne user for reporting the flaw, highlighting the importance of bug bounty programs. Customers with self-hosted gateways are advised to update immediately, while those with GitLab-hosted gateways do not need to take action. No workaround is listed for gateways that cannot be updated, and no information is available on whether the flaw has been used in attacks. The vulnerability underscores the importance of maintaining up-to-date software and prioritizing security when deploying AI models.
A recent vulnerability discovery has shed light on a critical flaw in GitLab's AI Gateway, a service that connects a GitLab instance to AI models. The vulnerability, tracked as CVE-2026-90970, has been rated critical by GitLab, with a CVSS score of 9.9 out of 10. This rating underscores the severity of the issue, which could potentially allow a logged-in user with Duo Agent Platform access to run commands on the gateway under certain conditions.
The AI Gateway is a crucial component of GitLab's platform, providing a connection between the user's GitLab instance and AI models. It is primarily used by organizations that host their own gateway, as this allows them to maintain control over their AI request and response data within their own environment. However, this very control also presents a security risk, as the gateway holds sensitive credentials such as signing keys for JSON Web Tokens (JWT).
According to GitLab, the vulnerability lies in the prompt template of a custom flow, which is an AI-powered workflow that users create on the Duo Agent Platform to automate multi-step tasks. A custom flow allows a logged-in user with Duo Agent Platform access to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said. This escape could lead to arbitrary command execution on the gateway, potentially allowing an attacker to execute commands on the gateway without the necessary permissions.
GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw, highlighting the importance of bug bounty programs in the identification of vulnerabilities. This is not the first vulnerability discovered in the AI Gateway by GitLab, as a similar flaw was reported earlier in February, CVE-2026-1868, which also had a CVSS score of 9.9. The new advisory does not mention this February flaw, indicating that the issue may have been patched.
Customers with self-hosted gateways are advised to update immediately, as the gateway version 19.2.4, 19.3.2, and 19.4.1 contain the fix for the vulnerability. However, for customers who use a GitLab-hosted gateway, no action is required, as the gateway has already been fixed by GitLab. Customers with self-managed instances that use a self-hosted gateway are strongly recommended to update immediately to mitigate the risk.
GitLab's maintenance policy has listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes. These are the same three lines that got the gateway fix, indicating that the patch was widely applied to minimize the window of exposure.
No workaround is listed for gateways that cannot be updated yet, and no information is available on whether the flaw has been used in attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an assessment to the CVE record on October 2, listing exploitation as "none." CISA's other two values cover a public proof of concept and active exploitation.
The vulnerability highlights the importance of maintaining up-to-date software and taking proactive measures to secure critical components of one's system. In this case, the critical flaw in the GitLab AI Gateway underscores the need for organizations to prioritize security when deploying AI models, especially in environments where sensitive data and systems are involved.
In the future, it is essential for organizations to stay vigilant and regularly check for security patches and updates. This can involve implementing a culture of continuous learning and improvement, where security is integrated into every aspect of the organization's operations.
Related Information:
https://www.ethicalhackingnews.com/articles/GitLab-AI-Gateway-Vulnerability-A-Critical-Flaw-Allows-Command-Execution-ehn.shtml
https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
Published: Fri Oct 2 12:58:31 2026 by llama3.2 3B Q4_K_M