Critical Vulnerability in GitLab’s AI Gateway Service Exposes Users to Remote Code Execution Attacks
A critical vulnerability has been discovered in GitLab’s AI Gateway service, a feature that provides access to artificial intelligence-powered tools within the company’s suite of services. The issue, tracked as CVE-2026-90970, allows attackers with basic privileges and Duo Agent Platform access to execute arbitrary commands on vulnerable instances, potentially leading to complete system compromise.
The vulnerability is particularly concerning because it affects not only GitLab’s cloud-based AI Gateway instance but also self-hosted instances deployed by users of GitLab Self-Managed. This means that thousands of organizations using the service may be at risk if they haven’t applied patches yet. The attack vector is relatively simple, as attackers can exploit the flaw even with basic privileges and access to the Duo Agent Platform.
GitLab has released patched versions (19.2.4, 19.3.2, and 19.4.1) specifically designed to address this vulnerability for self-hosted AI Gateway users. The company is urging all customers using a self-hosted AI Gateway installation to update to one of these versions immediately. Users with cloud-based AI Gateway instances do not need to take any action, as GitLab has already applied the necessary patches.
This latest vulnerability serves as a reminder of the importance of keeping software up-to-date and secure, especially in environments where sensitive data is being processed or stored. The discovery also highlights the ongoing threat posed by artificial intelligence-powered attacks, which can often evade traditional security measures.
The news comes on the heels of another critical vulnerability patched by GitLab just last month, which allowed unauthenticated attackers to read sensitive data from vulnerable servers. This incident underscores the need for organizations to prioritize cybersecurity and stay vigilant against emerging threats.
As a practical takeaway, users of GitLab’s AI Gateway service should review their current configuration and ensure they have applied the latest patches as soon as possible. Additionally, it is essential to keep all software and dependencies up-to-date, as this can significantly reduce the risk of exploitation by attackers. By taking proactive steps to secure their systems, organizations can minimize the risk of falling victim to these types of attacks and protect sensitive data from unauthorized access.
Source: Bleeping Computer — 2026-10-02