CriticalVulnerability
CVE-2026-90970: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-90970
- Published
- Record updated
Summary
GitLab fixed a vulnerability in its AI Gateway component, CVE-2026-90970, affecting versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Under certain conditions, an authenticated user with Duo Agent Platform access could escape the prompt template sandbox through a specially crafted flow configuration and execute arbitrary commands on the AI Gateway.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoGoogle is launching a one-stop Gemini agent for your work tasksSame vendor · The Verge (AI)
- InfoThe Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute VideosSame vendor · Wired (Security)
- InfoAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessSame vendor · SecurityWeek
- LowFake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesSame vendor · The Hacker News