GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
The Hacker News
Read the full articleGitLab patched a critical vulnerability (CVE-2026-90970) in its AI Gateway that allowed command execution by logged-in users with Duo Agent Platform access on self-hosted servers. The flaw affects gateway versions before 19.2.4, 19.3.2, and 19.4.1, and GitLab urges immediate updates for self-hosted instances.



