1 story

Safety & Security

GitLab fixes a 9.9-rated flaw in its self-hosted AI gateway

A user of GitLab’s Duo Agent Platform could escape a prompt template’s sandbox and run commands on the server. GitLab says its own hosted gateways are already fixed.

GitLab released fixes on October 2 for CVE-2026-90970, a critical flaw in its AI Gateway, the service that connects GitLab’s AI features to models. A logged-in user with access to the Duo Agent Platform could send a crafted flow configuration and run any command on the gateway.