Skip to main content

Tag: cve 2026 90970

2 articles

Brightly-lit server room interior with AI Gateway device centered.

GitLab Fixes 9.9 Flaw in AI Gateway That Enables Command Execution

GitLab has patched a critical 9.9-rated flaw in its AI Gateway that allowed attackers to execute commands, giving logged-in users with access to the Duo Agent Platform the potential to wreak havoc. This fix comes courtesy of HackerOne reporter invisiblemeerkat, who identified the vulnerability.

Analyst 207
Modern server room with equipment racks, servers, and gateway device surrounded by cables and networking gear.

GitLab patches RCE flaw in AI Gateway service

GitLab has patched a critical remote-code-execution flaw in its AI Gateway service, known as CVE-2026-90970, which could have allowed attackers to run arbitrary commands on vulnerable instances. Even users with basic privileges could exploit this vulnerability, making it essential to apply the patch ASAP.

Analyst 207