Cybersecurity · 1 view
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab fixed CVE-2026-90970, a 9.9 AI Gateway flaw that could let logged-in Duo Agent Platform users run commands on self-hosted gateways.
AI Summary
GitLab disclosed a critical vulnerability in its AI Gateway that allows a logged‑in user with Duo Agent Platform access to execute commands on the gateway under specific conditions. The flaw affects only self‑hosted deployments that run the gateway service connecting GitLab instances to AI models. GitLab’s advisory urges organizations operating their own AI Gateway to apply the patch promptly.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- Warlock ransomware breach SharePoint in water, telecom operator attacksContinue reading
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day ResponseContinue reading
- SWIFT Banking & Government Middleware Enables RCEContinue reading
- GitLab warns of critical RCE vulnerability in AI Gateway serviceContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow