Back to all lessons
Awareness Lessons
last week

Critical RCE in GitLab AI Gateway Demands Immediate Patching

A critical remote code execution vulnerability (CVE-2026-90970) in GitLab's AI Gateway service allows authenticated users to break out of a prompt template sandbox and execute arbitrary commands on self-hosted deployments — a severe risk given that authenticated access can still lead to full system compromise. This matters because AI-integrated services are rapidly expanding the attack surface of development platforms, and sandbox escapes in AI components represent an emerging and underappreciated threat vector. The fact that a second maximum-severity vulnerability (CVE-2026-85706) was simultaneously added to CISA's actively exploited list underscores that GitLab environments are under active threat. Self-hosted deployments are particularly exposed because they lack the automatic protections that cloud-hosted instances receive, placing the remediation burden entirely on operators.

Tactical Insight

Immediate Actions

  • Upgrade all self-hosted GitLab AI Gateway instances to patched versions 19.2.4, 19.3.2, or 19.4.1 without delay.
  • Audit and restrict which authenticated users have access to the Duo Agent Platform until patching is confirmed complete.
  • Verify cloud-hosted GitLab instances are already on protected versions and confirm with your vendor if uncertain.

Long-Term Improvements

  • Establish an emergency patching SLA (e.g., 24–72 hours) specifically for critical/RCE-class vulnerabilities on internet-facing developer infrastructure.
  • Maintain a continuously updated inventory of all self-hosted GitLab components, including AI Gateway services, to eliminate blind spots during future patch cycles.
  • Apply the principle of least privilege to AI service integrations, limiting which roles and users can invoke agentic or sandbox-capable features.

Detection Measures

  • Subscribe to GitLab Security Advisories and CISA's Known Exploited Vulnerabilities (KEV) catalog to receive real-time alerts on newly disclosed critical flaws.
  • Deploy behavioral monitoring and anomaly detection on AI Gateway services to flag unexpected command execution or unusual API call patterns.
  • Implement centralized logging for all AI Gateway interactions to support rapid forensic investigation if exploitation is suspected.