Back to advisories

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in weeks, with CVE-2026-85706 already actively exploited.

CRITICALAdvisoryOct 04, 2026
Action required
Immediately identify and patch all self-hosted GitLab AI Gateway instances to versions 19.2.4, 19.3.2, or 19.4.1. Hunt for exploitation attempts targeting Duo Agent Platform access and monitor for suspicious command execution in AI Gateway logs.
Affected products
GitLabGitLab AI GatewayGitLab Duo