GitLab Patches Critical AI Gateway Vulnerability (CVE‑2026‑90970)
GitLab has issued an emergency update to address a high‑severity flaw in its AI Gateway component, identified as CVE‑2026‑90970 and assigned a CVSS rating of 9.9. The vulnerability, described as critical by security researchers, could allow attackers with legitimate Duo authentication to break out of the gateway's prompt sandbox and run arbitrary commands on self‑hosted installations.
The issue stems from insufficient isolation in the AI Gateway's execution environment. Authenticated Duo users—who normally have limited access—could exploit the flaw to bypass the sandbox that isolates AI prompts, granting them the ability to execute system‑level commands on the host machine. Because many enterprises run GitLab’s AI services on private infrastructure, the potential impact ranges from data leakage to full system compromise.
GitLab’s AI Gateway serves as the bridge between its core platform and integrated large‑language‑model services, enabling developers to embed AI‑driven assistance directly into code review, issue triage, and CI/CD pipelines. The feature’s popularity has grown rapidly, especially among organizations that prefer on‑premises deployments for compliance reasons. A breach in this layer could undermine trust in the broader AI augmentation ecosystem that GitLab is building.
In response, GitLab released patches for the affected component and urged all customers operating self‑hosted gateways to apply the updates immediately. The company also published detailed remediation guidance, including steps to verify patch installation and recommendations for rotating credentials that might have been exposed. Security Affairs, the outlet that first reported the flaw, noted that the rapid disclosure and fix demonstrate GitLab’s commitment to addressing supply‑chain risks in its AI offerings.
The discovery highlights the growing attack surface introduced by AI integrations across software development tools. Analysts predict that vendors will intensify security audits of AI‑related modules, and regulators may scrutinize the safeguards around sandboxing and authentication. GitLab has pledged to conduct a thorough review of its AI codebase and to work with the broader open‑source community to harden future releases against similar exploits.
Comments (0)
Be the first to comment.
Join the discussion