Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Pashinyan Confronts the Karabakh Cause

    October 3, 2026

    UAE investigators say Omani Flydubai co-pilot was planning ‘terrorist’ attack

    October 3, 2026

    ‘People are deserting it’: why are London mansions struggling to sell? | Property

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Pashinyan Confronts the Karabakh Cause
    • UAE investigators say Omani Flydubai co-pilot was planning ‘terrorist’ attack
    • ‘People are deserting it’: why are London mansions struggling to sell? | Property
    • Circuit Breaker Labs hopes to make AI safer for your kids (and you)
    • Meta, OpenAI and Uber Just Taught AI Agents to Talk First. What About When to Stay Quiet?
    • The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
    • Trump expected to pick Clayton as AI czar
    • Women shoulder the burden of expanding wildfires in rural India
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GitLab warns of critical RCE vulnerability in AI Gateway service

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.

    AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instances on GitLab Self-Managed through GitLab Duo Self-Hosted.

    Tracked as CVE-2026-90970, this security flaw stems from an improper neutralization weakness and can let attackers with basic privileges and Duo Agent Platform access execute arbitrary commands on unpatched instances.

    “GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway,” the company explained in a Friday advisory.

    GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address this vulnerability for Self-Hosted AI Gateway users and said that customers using a GitLab-hosted AI Gateway are already protected and do not need to take action.

    “These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately,” it said. “We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance.”

    GitLab added that it reached out to those who host their own AI Gateway before disclosure and urged users to upgrade vulnerable instances as soon as possible.

    Last month, GitLab also patched a maximum severity path traversal vulnerability (CVE-2026-85706) in GitLab Community Edition (CE) and Enterprise Edition (EE) that allows unauthenticated attackers to read sensitive data such as credentials and other secrets from vulnerable servers.

    One day later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its list of actively exploited flaws and gave federal agencies three days to secure their systems as mandated by Binding Operational Directive (BOD) 26-04.

    Since November 2021, CISA has tagged five GitLab vulnerabilities abused in the wild, including one exploited by ransomware gangs.

    GitLab’s DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    critical gateway GitLab RCE Service Vulnerability warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

    London Labour council warns it may raise council tax by 150% | Local government

    Warlock ransomware breach SharePoint in water, telecom operator attacks

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Pashinyan Confronts the Karabakh Cause

    October 3, 2026

    UAE investigators say Omani Flydubai co-pilot was planning ‘terrorist’ attack

    October 3, 2026

    ‘People are deserting it’: why are London mansions struggling to sell? | Property

    October 3, 2026

    Circuit Breaker Labs hopes to make AI safer for your kids (and you)

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Pashinyan Confronts the Karabakh Cause

    October 3, 2026

    UAE investigators say Omani Flydubai co-pilot was planning ‘terrorist’ attack

    October 3, 2026

    ‘People are deserting it’: why are London mansions struggling to sell? | Property

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.