INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitLab AI Gateway Flaw Allows Command Execution Without Credentials

| 2026-10-02 17:33 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
GitLab has fixed a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway. The flaw was disclosed by GitLab on October 2 and patched with releases of versions 19.2.4, 19.3.2, and 19.4.1. Affected AI Gateway releases include those from version 18.1.6 through 19.2.3, as well as specific versions in the range of 19.3.0 to 19.4.1. GitLab credited HackerOne researcher invisiblemeerkat with responsibly reporting the vulnerability. The security fix has already been deployed to its own hosted AI Gateways and customers using GitLab.com or a self-managed instance connected to a gateway do not need to take action, as the flaw is fixed in these environments.
Technical Mitigations AI-generated
• Implement a Content Security Policy (CSP) to restrict the execution of scripts and stylesheets in custom flow prompt templates. • Validate user input for custom flow configuration to prevent specially crafted flow configurations from escaping the prompt template sandbox. • Regularly update AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 or later to patch the critical vulnerability. • Implement Duo Agent Platform access controls with strict permissions and monitoring to limit potential exploitation of the flaw. • Use a web application firewall (WAF) to detect and block malicious traffic targeting the AI Gateway.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

pl•••••.open
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-1868CVE-2026-1868 CVE-2026-55245CVE-2026-55245 CVE-2026-90970CVE-2026-90970 CVE-2026-90898CVE-2026-90898 CVE-2026-86242CVE-2026-86242
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎April 2026
Researchers disclosed a design flaw in the STDIO transport that affects Anthropic's official SDKs.
organisation STDIO
‎September 6
A second, related flaw was disclosed by Or Peles on September 6.
‎Sep 22, 2026
Threat actors exploited a critical vulnerability in GitLab's 9.9 AI Gateway, allowing command execution on self-hosted servers, which was patched on the specified target date.
‎Oct 02, 2026
Threat actors exploited a critical 9.9 AI Gateway flaw, tracked as CVE-2026-90970, allowing command execution on self-hosted servers using gateway versions prior to 19.2.4 and later than 18.1.6.
infrastructure 19.2.4
infrastructure 19.3.2
infrastructure 19.4.1
infrastructure 18.1.6
infrastructure 19.3
infrastructure 19.4
infrastructure 4.1-ee
organisation Docker
infrastructure 19.1
infrastructure 9.9
organisation AI Gateways
organisation GitLab.com
organisation GitLab Dedicated
organisation JWT
organisation HackerOne
‎October 2
GitLab disclosed a critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers, which was subsequently patched with releases 19.2.4, 19.3.2, and 19.4.1.
vulnerability CVSS score of 9.9
organisation CVSS
infrastructure 19.3
infrastructure 19.4
infrastructure 19.2
general_metric 19.4 policy
general_metric 19.2 policy
infrastructure 19.2.4
infrastructure 19.3.2
infrastructure 19.4.1
vulnerability CVE-2026-90970
‎2026/10/02
Threat actors could potentially exploit a critical vulnerability in GitLab's AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), allowing an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on self-hosted servers under certain conditions.
infrastructure 19.2.4
infrastructure 19.3.2
infrastructure 19.4.1
infrastructure 18.1.6
infrastructure 19.2.3
infrastructure 19.3.0
infrastructure 19.3.1
infrastructure 19.4.0
organisation CVE-2026-90970
infrastructure 9.9
organisation GitLab
organisation Vulnerability / Application Security
organisation AI Gateway
organisation AI Gateways
organisation GitLab.com
organisation HackerOne
organisation The GitLab AI Gateway
infrastructure 9.8
infrastructure 2.1.0
organisation Bifrost
organisation MCP
organisation POST
organisation API
organisation /api/mcp
organisation Operators
organisation JFrog
organisation Neither Bifrost CVE
organisation KEV
Tactical Metrics
Metrics
infrastructure
‎19.2.4
Software Version
Metrics
infrastructure
‎19.3.2
Software Version
Metrics
infrastructure
‎19.4.1
Software Version
Metrics
infrastructure
‎18.1.6
Software Version
Metrics
infrastructure
‎19.3
Software Version
Metrics
infrastructure
‎19.4
Software Version
Metrics
infrastructure
‎4.1-ee
Software Version
Metrics
infrastructure
‎19.1
Software Version
Metrics
infrastructure
‎19.2
Software Version
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
‎19.2.3
Software Version
Metrics
infrastructure
‎19.3.0
Software Version
Metrics
infrastructure
‎19.3.1
Software Version
Metrics
infrastructure
‎19.4.0
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎2.1.0
Software Version