Tag: cve 2026 90970
2 articles

GitLab Fixes 9.9 Flaw in AI Gateway That Enables Command Execution
GitLab has patched a critical 9.9-rated flaw in its AI Gateway that allowed attackers to execute commands, giving logged-in users with access to the Duo Agent Platform the potential to wreak havoc. This fix comes courtesy of HackerOne reporter invisiblemeerkat, who identified the vulnerability.

GitLab patches RCE flaw in AI Gateway service
GitLab has patched a critical remote-code-execution flaw in its AI Gateway service, known as CVE-2026-90970, which could have allowed attackers to run arbitrary commands on vulnerable instances. Even users with basic privileges could exploit this vulnerability, making it essential to apply the patch ASAP.