GitLab disclosed a critical flaw in its AI Gateway, the service that connects a GitLab instance to AI models, that could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions. Tracked as CVE-2026-90970 and rated 9.9, it is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. Only organizations that host their own gateway need to act; customers using a GitLab-hosted gateway are already fixed. GitLab strongly recommends self-hosted gateway operators update immediately and notified them before publishing. CISA's record currently lists exploitation as none.