GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command… | HappeningNow.news

Cybersecurity · 1 view

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab fixed CVE-2026-90970, a 9.9 AI Gateway flaw that could let logged-in Duo Agent Platform users run commands on self-hosted gateways.

Source AI Summary Published 1h 40m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 1 Community interest
Brief read Under 1 min brief 59 words

AI Summary

GitLab disclosed a critical vulnerability in its AI Gateway that allows a logged‑in user with Duo Agent Platform access to execute commands on the gateway under specific conditions. The flaw affects only self‑hosted deployments that run the gateway service connecting GitLab instances to AI models. GitLab’s advisory urges organizations operating their own AI Gateway to apply the patch promptly.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at The Hackernews

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page