[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foDR7DT1tmGWMcWNOc-AJt3cA-dD-hwUdC_zp1R0Vt1c":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"929c38b0-7b41-44fb-a29a-173269be38c5","critical-gitlab-ai-gateway-flaw-enables-remote-command-execution","2eb9ab9d-9836-434f-96d8-cc097b1d7235","Critical GitLab AI Gateway Flaw Enables Remote Command Execution","A critical vulnerability (CVE-2026-90970) in GitLab's AI Gateway, scoring 9.9 on the CVSS scale, allows any authenticated user with Duo Agent Platform access to execute arbitrary commands on self-hosted servers — a near-worst-case privilege escalation scenario. The flaw highlights the expanding attack surface introduced by AI-integrated components, which may not receive the same security scrutiny as core platform features. Because self-hosted GitLab instances often sit at the heart of software development pipelines, exploitation could compromise source code, credentials, and CI\u002FCD workflows at scale. The fact that only a valid login is required — rather than admin privileges — dramatically lowers the bar for exploitation and underscores the urgency of patching.","**Immediate actions:**\n- Apply GitLab's released patch for CVE-2026-90970 to all affected AI Gateway versions without delay.\n- Audit which user accounts have Duo Agent Platform access and temporarily restrict that permission until patching is confirmed.\n- Verify self-hosted GitLab instances are not directly exposed to the internet while the patch is being deployed.\n\n**Long-term improvements:**\n- Establish an emergency patching SLA (e.g., ≤24 hours) for vulnerabilities rated CVSS 9.0 or above affecting internet-facing or development infrastructure.\n- Maintain a continuously updated inventory of all GitLab components, including AI add-ons and integrations, to ensure no assets are missed during patch cycles.\n- Apply the principle of least privilege to AI platform features, granting Duo Agent Platform access only to roles that explicitly require it.\n\n**Detection measures:**\n- Enable and centrally collect GitLab audit logs to detect anomalous command execution or privilege escalation attempts originating from AI Gateway interactions.\n- Deploy a vulnerability scanner configured to alert on newly published CVEs affecting GitLab and its components within 24 hours of disclosure.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 1: Inventory and Control of Enterprise Assets","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","NIST CSF RS.MI-3: Newly Identified Vulnerabilities Mitigated","ITIL: Change and Release Management (emergency change process)","published","2026-10-02T18:20:40.691911+00:00","2026-10-02T18:20:40.621+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fgitlab-patches-critical-self-hosted-ai.html","gitlab-patches-critical-9-9-ai-gateway-flaw-allowing-command-execution-on-self-h-5ef20b","GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[42],{"id":43,"date":44,"edition":45,"title":46,"audio_url":47},"1ea7e401-40de-47ea-9515-ea1dfb7a5c0e","2026-10-03","morning","ThreatNoir Weekend Brief — October 3","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-10-03\u002Fthreatnoir-morning-brief-2026-10-03.mp3"]