CVE-2026-90970
published 2026-10-02CVE-2026-90970: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before…
PriorityP269critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.94%
59.8th percentile
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | gitlab_ai_gateway | — | — |
| gitlab | gitlab_ai_gateway | >= 18.1.6 < 19.2.4 | 19.2.4 |
| gitlab | gitlab_ai_gateway | >= 19.3 < 19.3.2 | 19.3.2 |
| gitlab | gitlab_ai_gateway | >= 19.4 < 19.4.1 | 19.4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
vendor_gitlab·2026-10-02·CVSS 9.9
CVE-2026-90970 [CRITICAL] CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Affected products: GitLab AI Gateway
Affected versions: >=18.1.6, =19.3, =19.4, <19.4.1 (affected)
Solution: Upgrade to version 19.2.4, 19.3.2, 19.4.1 or above.
Credit: Thanks [invisiblemeerkat](https://hackerone.com/invisiblemeerkat) for responsibly disclosing this issue
GHSA
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under cert
ghsa_unreviewed·2026-10-02
CVE-2026-90970 [CRITICAL] CWE-1336 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under cert
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
blogs_hackernews·2026-10-05·CVSS 7.5
CVE-2026-88779 [HIGH] ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.
There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.
Here’s what mattered this week.
## ⚡ Threat of the Week
Citrix Warns of Ne
Checkpoint
5th October – Threat Intelligence Report
blogs_checkpoint·2026-10-05
CVE-2026-88771 5th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports dating back to 2010, exposing personal and case-related information belonging to current and former participan
Hackernews
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
blogs_hackernews·2026-10-02·CVSS 9.9
CVE-2026-90970 [CRITICAL] GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory .
The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The flaw is tracked as CVE-2026-90970 . GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
GitLab runs AI Gatewa
2026-10-02
Published