GitLab Patches Critical AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab has released patches for CVE-2026-90970, a critical vulnerability in its AI Gateway service that allows authenticated users to execute arbitrary commands. The flaw, rated 9.9 on the CVSS scale, affects only self-hosted instances; GitLab-managed services are already secured. Users must update to versions 19.2.4, 19.3.2, or 19.4.1 immediately.
Key points
- The vulnerability, tracked as CVE-2026-90970, enables arbitrary command execution on the AI Gateway host.
- It affects only self-hosted AI Gateway deployments; GitLab-managed instances are already patched.
- Fixed versions are 19.2.4, 19.3.2, and 19.4.1.
- CISA assessed the exploitation status as 'none' as of October 2, 2026.
- No workaround exists, and there is no reliable method to detect prior compromise.
Background
This incident follows a similar critical flaw (CVE-2026-1868) patched in February 2026, also rated 9.9 and involving the same template-engine weakness. GitLab has faced multiple critical vulnerabilities recently, including a path traversal flaw (CVE-2026-85706) added to CISA's actively exploited list in September 2026.
How outlets are covering it
BleepingComputer and The Hacker News emphasize the immediate need for self-hosted users to patch, noting GitLab's targeted outreach. InfoQ focuses on the broader context of active exploitation of other GitLab flaws, highlighting the risk of unauthenticated data exfiltration. Forkast.news draws parallels to other AI infrastructure sandbox escapes, stressing the recurring nature of template-engine vulnerabilities in AI platforms. All sources agree on the critical severity and the lack of a workaround.
Why it matters
The AI Gateway holds sensitive JWT signing keys and connects to AI model providers, making it a high-value target. A compromise could lead to unauthorized access to AI-integrated workflows and authentication tokens, potentially impacting CI/CD pipelines and other connected systems.
What to watch
Self-hosted GitLab users must update to the patched versions immediately. Organizations should monitor for any signs of compromise, though no detection method is currently available. GitLab may release further guidance or patches for older versions if needed.
- GitLab warns of critical RCE vulnerability in AI Gateway service BleepingComputer
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News
- GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration infoq.com
- GitLab Patches Critical AI Gateway RCE Vulnerability — Prompt Template Sandbox Escape Rated CVSS 9.9 forkast.news
- GitLab patches the 9.9 CVE-2026-90970 vulnerability in its AI Gateway Pasquale Pillitteri
Want the full story? Read the original reporting
Read on BleepingComputer