GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
About this summary. This is a short, independently written summary of an article first published by Security Affairs. Cyber Security News did not report or verify the underlying story. Read the original: https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html

Source attribution: headline and facts are from Security Affairs (securityaffairs.com). Summary method: excerpt of the source description. See our source attribution policy.






