GitLab warns of critical RCE vulnerability in AI Gateway service

Critical Vulnerability Exposed in GitLab’s AI Gateway Service, Users Urged to Patch Immediately

A critical vulnerability has been discovered in GitLab’s AI Gateway service, a feature that allows users to access AI-native capabilities within the platform. The flaw, tracked as CVE-2026-90970, could enable attackers with basic privileges and Duo Agent Platform access to execute arbitrary commands on unpatched instances. This exploit is considered particularly concerning due to its potential impact.

The vulnerability affects self-hosted instances of GitLab Self-Managed and those using GitLab Duo Self-Hosted. However, it’s worth noting that users who rely on the cloud-based AI Gateway instance hosted by GitLab are already protected and do not need to take action. To address this issue, GitLab has released patch versions 19.2.4, 19.3.2, and 19.4.1 for Self-Hosted AI Gateway users.

It’s essential to understand how the vulnerability works in order to grasp its severity. The flaw stems from an improper neutralization weakness, allowing attackers to bypass certain security restrictions within the platform. This means that even users with basic privileges could potentially execute arbitrary commands on vulnerable instances.

The discovery of this critical vulnerability is particularly noteworthy given GitLab’s significant user base and the reliance many organizations have on the platform for their operations. With over 30 million registered users, including some of the world’s largest companies such as Nvidia and Lockheed Martin, the potential impact of a successful exploit is substantial.

Furthermore, this incident serves as a reminder of the importance of patching vulnerabilities in time-sensitive manner. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been actively monitoring GitLab vulnerabilities, including several that have been exploited in the wild since November 2021. It’s crucial for users to stay informed about security patches and updates to protect their systems.

In light of this vulnerability, it is imperative that Self-Hosted AI Gateway users update their instances with the latest patch versions as soon as possible. This will not only mitigate the risk of an exploit but also demonstrate a proactive approach to cybersecurity within organizations.


Source: Bleeping Computer — 2026-10-02