Particle.news

GitLab Urges Immediate Patch for Critical AI Gateway RCE

Self-hosted AI Gateway instances hold signing keys so the flaw could let an authenticated Duo user run commands on gateway hosts.

Overview

  • GitLab disclosed the issue on October 2 and released patched AI Gateway builds 19.2.4, 19.3.2, and 19.4.1 while saying its GitLab-managed gateways have already been remediated.
  • The flaw, tracked as CVE-2026-90970 and rated critical with a 9.9 CVSS score, lets an authenticated user with Duo Agent Platform access escape a prompt-template sandbox and execute arbitrary commands on a vulnerable gateway.
  • Only customers running self-hosted AI Gateway installations need to act because GitLab.com, GitLab Dedicated, and instances using GitLab-hosted gateways were fixed by the company.
  • CISA added a note to the CVE record saying it has observed no exploitation, but GitLab’s advisory does not provide detection steps or a workaround for gateways that cannot be updated yet.
  • A compromised self-hosted gateway could expose JWT signing keys and connections to internal GitLab instances and AI providers, which could give attackers a foothold inside an organization and make rapid patching essential.