GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)
Vulnerability
Summary
Hide ▲
Show ▼
GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands on vulnerable self-hosted instances. The issue affects GitLab Self-Hosted AI Gateway deployments, while GitLab-hosted AI Gateway users are already protected. GitLab released 19.2.4, 19.3.2, and 19.4.1 and told customers to update immediately.
Related Happenings
GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)
Advisory/Mitigation
H score41
First: 02.10.2026 19:20
Last: 02.10.2026 19:20
Sources 1
How related:
GitLab strongly recommends that those customers update immediately.
About this happening:
GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arb...
GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)
Advisory/MitigationHow related: GitLab strongly recommends that those customers update immediately.
About this happening: GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arb...
GitLab incoming email token auth bypass security flaw
Vulnerability
H score22
First: 23.09.2026 19:53
Last: 23.09.2026 19:53
Sources 1
About this happening:
GitLab's incoming email token lets a holder act as the account owner, creating unauthorized commit and CI/CD execution risk across projects the user can access. The fe...
GitLab incoming email token auth bypass security flaw
VulnerabilityAbout this happening: GitLab's incoming email token lets a holder act as the account owner, creating unauthorized commit and CI/CD execution risk across projects the user can access. The fe...
GitLab CE/EE repository commits API path traversal (CVE-2026-85706)
Vulnerability
H score43
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
CISA added CVE-2026-85706 to its actively exploited catalog after GitLab CE/EE servers were probed and attacked, increasing the risk of credential and secret disclosure*...
GitLab CE/EE repository commits API path traversal (CVE-2026-85706)
VulnerabilityAbout this happening: CISA added CVE-2026-85706 to its actively exploited catalog after GitLab CE/EE servers were probed and attacked, increasing the risk of credential and secret disclosure*...
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector Action
H score36
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector ActionAbout this happening: CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
GitLab self-managed installations immediate upgrade advisory
Advisory/Mitigation
H score45
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
About this happening:
GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
GitLab self-managed installations immediate upgrade advisory
Advisory/MitigationAbout this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
Timeline
-
02.10.2026 19:20 3 articles · 1h ago
GitLab warns of critical CVE-2026-90970 in GitLab AI Gateway and releases fixes
Initial DisclosureGitLab warned that CVE-2026-90970 in GitLab AI Gateway could let an authenticated user with Duo Agent Platform access escape the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on vulnerable GitLab Self-Hosted AI Gateway instances. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 for GitLab Self-Managed customers and said GitLab-hosted AI Gateway users are already protected.
Show sources
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers — thehackernews.com — 02.10.2026 20:33