GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
- Published
- Record updated
Summary
GitLab disclosed CVE-2026-90970, a critical flaw rated 9.9 in the AI Gateway that lets a logged-in user with Duo Agent Platform access escape the prompt template sandbox through a specially crafted flow configuration. The escape could lead to arbitrary command execution on the gateway, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Mitigation
Fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. GitLab strongly recommends that self-hosted gateway customers update immediately. For Docker deployments, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee. Helm deployments set the new tag in the chart's image setting.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database