GitLab Fixes critical vulnerabilities in AI gateway, RCE; CVSS rating
2026-10-03 15:41:22
CoinMeta Data: GitLab has released a patch for CVE-2026-90970, fixing a critical vulnerability that affected its AI gateway. This vulnerability has a CVSS score of 9.9, allowing authenticated users with access to the Duo Agent platform to execute arbitrary commands on the underlying host. This is the first critical remote code execution vulnerability discovered in a specific infrastructure component of AI. The vulnerability stems from inadequate cleaning of user-provided stream configuration data; the AI gateway uses Jinja2-style template placeholders to process this configuration. Since the input was not properly neutralized, attackers could manipulate the template engine to perform sandbox escape. GitLab has been fixed for managed instances, but self-managed users must manually update to versions 19.2.4, 19.3.2, or 19.4.1.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.