GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

The Hacker News
Read the full article
GitLab patched a critical vulnerability (CVE-2026-90970) in its AI Gateway that allowed command execution by logged-in users with Duo Agent Platform access on self-hosted servers. The flaw affects gateway versions before 19.2.4, 19.3.2, and 19.4.1, and GitLab urges immediate updates for self-hosted instances.

More in Cybersecurity

Man Charged With Illegally Shipping Nvidia Chips to China

Covered by 4 sources
Cybersecurity5 min read

OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers

Covered by 3 sources
Cybersecurity1 min read

California issues investigative subpoena to OpenAI over rogue agents’ hacking

Covered by 2 sources