GitLab is urging customers to immediately patch a critical vulnerability in its AI Gateway service that could allow attackers to execute arbitrary commands on affected systems. The flaw, tracked as CVE-2026-90970, stems from an improper neutralization weakness and can be exploited by attackers holding only basic privileges along with access to the Duo Agent Platform. According to GitLab, an authenticated user with that access could escape the prompt template sandbox through a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway. The company issued the warning in a Friday advisory.

The AI Gateway provides access to GitLab's AI-native Duo features. GitLab runs its own cloud-based instance serving GitLab.com, GitLab Self-Managed, and GitLab Dedicated customers, but organizations can also operate their own self-hosted AI Gateway deployments through GitLab Duo Self-Hosted. GitLab said customers relying on its hosted AI Gateway are already protected and need not take any action. The remediation applies specifically to those running the self-hosted version.

GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the vulnerability for Self-Hosted AI Gateway users. The company strongly recommended that all GitLab Self-Managed customers with Self-Hosted AI Gateway installations upgrade to one of these versions immediately. GitLab also said it conducted targeted outreach to Self-Hosted AI Gateway customers ahead of the release and urged them to upgrade vulnerable instances as soon as possible.

The disclosure follows a separate GitLab security episode last month. GitLab patched a maximum severity path traversal vulnerability, CVE-2026-85706, in GitLab Community Edition and Enterprise Edition that allowed unauthenticated attackers to read sensitive data, including credentials and other secrets, from vulnerable servers. One day later, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-85706 to its list of actively exploited flaws and gave federal agencies three days to secure their systems under Binding Operational Directive BOD 26-04. The regulatory action gives the earlier flaw a direct US government angle.

CISA has tagged five GitLab vulnerabilities as exploited in the wild since November 2021, including one used by ransomware gangs. GitLab's DevSecOps platform reports more than 30 million registered users and counts over 50 percent of Fortune 100 companies among its customers, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS. The scale of that adoption underscores why flaws in GitLab components draw rapid attention from both defenders and attackers.

Enterprises running self-hosted AI infrastructure should treat the AI Gateway fix as a priority, given that the defect permits command execution rather than mere data exposure. GitLab has not reported any active exploitation of CVE-2026-90970, and its guidance remains limited to applying the listed versions and confirming whether a deployment uses the self-hosted gateway. Customers on GitLab's hosted service fall outside the remediation scope.

More cybersecurity news from TechManNews.