Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent Update: GitLab AI Gateway Vulnerability

Urgent Update: GitLab AI Gateway Vulnerability

Posted on October 3, 2026 By CWS

GitLab has issued a crucial security update to patch a severe vulnerability in its AI Gateway, potentially allowing remote command execution by authenticated users. The flaw, marked as CVE-2026-90970, holds a CVSS score of 9.9, impacting self-hosted setups that facilitate GitLab Duo AI functions.

Immediate Update Recommendations

To mitigate this threat, GitLab has rolled out AI Gateway versions 19.2.4, 19.3.2, and 19.4.1. Users of affected self-hosted gateways are urged to upgrade without delay. Prior to the public release of its security bulletin, GitLab proactively reached out to its self-hosted AI Gateway customers, offering early guidance on the necessary updates.

Details of the AI Gateway Flaw

The vulnerability stems from improper management of custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could craft a flow configuration that bypasses the prompt template sandbox. Exploiting this vulnerability could enable execution of arbitrary commands on the AI Gateway.

Sandboxes are designed to keep operations within a secure boundary. However, GitLab indicates that crafted inputs could breach this boundary and enable command execution, posing a significant risk beyond altering AI responses, potentially affecting the service processing the AI requests.

Impact and Exploitation Concerns

The CVSS vector indicates a network-accessible attack requiring low complexity and privileges, with no user interaction needed. While the flaw demands valid Duo Agent Platform access, it remains critical due to its potential impact on confidentiality, integrity, and availability.

GitLab credited security researcher invisiblemeerkat for discovering and responsibly reporting the issue. The advisory does not disclose any exploit payloads, the specific template engine involved, or active exploitation cases, but it highlights a significant security gap.

Versions affected include those from 18.1.6 up to before 19.2.4, and earlier releases in the 19.3 and 19.4 branches. Administrators should verify their gateway deployments rather than relying solely on their main GitLab instance versions.

Action Steps for Administrators

GitLab has implemented the fix for its hosted AI Gateways, ensuring that customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-hosted AI Gateway are secure without further action. However, those managing their own affected AI Gateways must apply the update manually.

This distinction is critical as GitLab’s self-hosted AI configuration allows organizations to manage backend model requests within their environments. It is vital for administrators to adhere to GitLab’s documentation for AI Gateway installation and upgrades to deploy the patched image effectively.

For Docker setups, GitLab advises stopping and removing the existing container, then pulling and running the new image with the correct environment variables, verifying the image digest, and running available health checks afterward.

In Kubernetes and Helm deployments, cached images might obstruct updated code from being pulled. GitLab recommends using image digests or setting an appropriate pull policy. Additionally, limiting unnecessary outbound gateway traffic while maintaining essential connections is advised for better security hardening. Nonetheless, installing the updated AI Gateway release remains the immediate priority.

Cyber Security News Tags:AI gateway, CVE-2026-90970, CVSS score, Cybersecurity, GitLab, GitLab Duo AI, IT security, Patch, remote code execution, security update, self-hosted deployments, system upgrade, technology news, Vulnerability

Post navigation

Previous Post: Debian Updates 1,313 Vulnerabilities to Prevent Security Risks
Next Post: Urgent Update: Dell Container Storage Security Vulnerabilities

Related Posts

Gemini API Keys Exploited in Telegram Fraud Scheme Gemini API Keys Exploited in Telegram Fraud Scheme Cyber Security News
Instagram Started Using 1-Week Validity TLS certificates and Changes Them Daily Instagram Started Using 1-Week Validity TLS certificates and Changes Them Daily Cyber Security News
Hackers Embed Commands in Emails to Exploit AI Systems Hackers Embed Commands in Emails to Exploit AI Systems Cyber Security News
Critical Updates for SolarWinds Serv-U Fix Major Security Flaws Critical Updates for SolarWinds Serv-U Fix Major Security Flaws Cyber Security News
BGP Hijack Targets Softaculous, Delivers Malicious Update BGP Hijack Targets Softaculous, Delivers Malicious Update Cyber Security News
OWASP Unveils AI Security Report for Enhanced Protection OWASP Unveils AI Security Report for Enhanced Protection Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability
  • Debian Updates 1,313 Vulnerabilities to Prevent Security Risks
  • Citrix NetScaler Reboot Issues Post-Patch
  • Session Cookie Flaw Risks Entra ID MFA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability
  • Debian Updates 1,313 Vulnerabilities to Prevent Security Risks
  • Citrix NetScaler Reboot Issues Post-Patch
  • Session Cookie Flaw Risks Entra ID MFA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark