Critical GitLab AI Gateway Flaw Lets Logged-In Users Run Commands: Patch Now
GitLab has disclosed a critical security flaw, CVE-2026-90970, in its AI Gateway, the service that connects GitLab instances to AI models. The flaw, rated 9.9 out of 10 on the CVSS scale, could allow a logged-in user with access to the Duo Agent Platform to run commands on the gateway under certain conditions. GitLab published the advisory on October 2.
The issue only affects organisations that run their own self-hosted AI Gateway, an option GitLab offers to customers who want to keep AI request and response data inside their own environment. Customers using GitLab.com, GitLab Dedicated, or a GitLab-hosted gateway on self-managed instances are not affected, as GitLab has already patched those on its side. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1; everything from version 18.1.6 through the 19.1 line remains vulnerable, with no fix currently listed for those older releases and no workaround available.
GitLab says it notified affected customers directly before publishing the advisory and is urging immediate updates. There is no confirmed evidence of active exploitation: CISA's assessment of the CVE, added the same day, lists exploitation status as 'none'. Still, the advisory does not explain whether older gateway versions will receive patches, nor does it offer a way to check if a gateway was compromised before updating.