Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical GitLab AI Gateway Vulnerability Patched

Critical GitLab AI Gateway Vulnerability Patched

Posted on October 2, 2026 By CWS

A critical vulnerability in GitLab’s AI Gateway has been addressed, preventing potential command execution by users with access to the Duo Agent Platform. This flaw, identified as CVE-2026-90970, affects organizations using self-hosted gateways and was disclosed on October 2, 2026.

Details of the Vulnerability

The AI Gateway connects GitLab instances to AI models, and the flaw could allow authenticated users to execute commands under certain conditions. GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1 to mitigate this risk. The issue has a CVSS score of 9.9 out of 10, emphasizing its severity.

While GitLab’s hosted services are already secured, organizations managing their own gateways are urged to apply these updates without delay. This recommendation was communicated to customers before the public advisory was issued.

Impact and Resolution

The flaw lies in the prompt template of a custom workflow on the Duo Agent Platform, which could be exploited to bypass the template sandbox. This exploitation might result in arbitrary command execution on the gateway.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has noted that there is currently no evidence of active exploitation. However, GitLab advises immediate updates to safeguard systems, as no workarounds are available for those unable to upgrade.

Updating Affected Systems

To update a Docker deployment of the gateway, administrators should stop the running container, remove it, and then deploy the updated image, such as self-hosted-v19.4.1-ee. For Helm deployments, the new image tag should be set in the chart’s configuration.

GitLab’s maintenance policy specifies that versions 19.2, 19.3, and 19.4 are eligible for security fixes, and these versions have received the necessary updates. Users are encouraged to ensure their systems align with these versions to maintain security integrity.

Conclusion and Future Outlook

This critical vulnerability highlights the need for continuous security vigilance in software environments. GitLab has credited the researcher ‘invisiblemeerkat’ on HackerOne for identifying this issue, underscoring the importance of collaborative security efforts.

Looking ahead, organizations should remain proactive in applying security patches and monitoring advisories to protect against potential threats. GitLab’s swift response to this flaw reflects its commitment to maintaining robust security for its users.

The Hacker News Tags:AI gateway, CISA, CVE-2026-90970, Docker, Duo Agent Platform, GitLab, Helm, security patch, self-hosted servers, Vulnerability

Post navigation

Previous Post: Critical cPanel/WHM Flaws Risk Server Security
Next Post: OpenClaw Unveils Free AI Agent Management Platform

Related Posts

Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions The Hacker News
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns The Hacker News
CISA Alerts on SharePoint Flaw Amidst Active Exploitation CISA Alerts on SharePoint Flaw Amidst Active Exploitation The Hacker News
Trapdoor Android Fraud Scheme Hijacks 659 Million Daily Requests Trapdoor Android Fraud Scheme Hijacks 659 Million Daily Requests The Hacker News
Exploited PaperCut Flaws Allow Unverified Code Execution Exploited PaperCut Flaws Allow Unverified Code Execution The Hacker News
DeepSeek Harness Flaw Allows AI Sandbox Bypass DeepSeek Harness Flaw Allows AI Sandbox Bypass The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark