Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: duo-agent (1 article)Clear

Critical GitLab AI Gateway flaw lets authorized users run commands on self-hosted servers

GitLab disclosed a critical flaw in its AI Gateway, the service that connects a GitLab instance to AI models, that could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions. Tracked as CVE-2026-90970 and rated 9.9, it is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. Only organizations that host their own gateway need to act; customers using a GitLab-hosted gateway are already fixed. GitLab strongly recommends self-hosted gateway operators update immediately and notified them before publishing. CISA's record currently lists exploitation as none.

Check
Determine whether your organization runs a self-hosted GitLab AI Gateway, and if so upgrade to 19.2.4, 19.3.2, or 19.4.1 immediately.
Affected
Self-hosted GitLab AI Gateways on affected versions let a logged-in user with Duo Agent Platform access run commands on the gateway server under certain conditions.
Fix
Update self-hosted gateways to the fixed versions, limit Duo Agent Platform access to trusted users, and monitor the gateway host for unexpected command execution.