INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitLab AI Gateway Flaw Allows Command Execution Without Credentials
| 2026-10-02 17:33 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
GitLab has fixed a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway. The flaw was disclosed by GitLab on October 2 and patched with releases of versions 19.2.4, 19.3.2, and 19.4.1. Affected AI Gateway releases include those from version 18.1.6 through 19.2.3, as well as specific versions in the range of 19.3.0 to 19.4.1. GitLab credited HackerOne researcher invisiblemeerkat with responsibly reporting the vulnerability. The security fix has already been deployed to its own hosted AI Gateways and customers using GitLab.com or a self-managed instance connected to a gateway do not need to take action, as the flaw is fixed in these environments.
Technical Mitigations AI-generated
• Implement a Content Security Policy (CSP) to restrict the execution of scripts and stylesheets in custom flow prompt templates.
• Validate user input for custom flow configuration to prevent specially crafted flow configurations from escaping the prompt template sandbox.
• Regularly update AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 or later to patch the critical vulnerability.
• Implement Duo Agent Platform access controls with strict permissions and monitoring to limit potential exploitation of the flaw.
• Use a web application firewall (WAF) to detect and block malicious traffic targeting the AI Gateway.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
pl•••••.open
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-1868CVE-2026-1868
CVE-2026-55245CVE-2026-55245
CVE-2026-90970CVE-2026-90970
CVE-2026-90898CVE-2026-90898
CVE-2026-86242CVE-2026-86242
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
April 2026
Researchers disclosed a design flaw in the STDIO transport that affects Anthropic's official SDKs.
Click on any entity below to view its context and source!
organisation
STDIO
In April 2026, researchers
disclosed a design flaw in MCP's STDIO transport
that affects Anthropic's official SDKs.
September 6
A second, related flaw was disclosed by Or Peles on September 6.
Sep 22, 2026
Threat actors exploited a critical vulnerability in GitLab's 9.9 AI Gateway, allowing command execution on self-hosted servers, which was patched on the specified target date.
Oct 02, 2026
Threat actors exploited a critical 9.9 AI Gateway flaw, tracked as CVE-2026-90970, allowing command execution on self-hosted servers using gateway versions prior to 19.2.4 and later than 18.1.6.
Click on any entity below to view its context and source!
infrastructure
19.2.4
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
No fixed version is listed below 19.2.4.
infrastructure
19.3.2
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
infrastructure
19.4.1
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
infrastructure
18.1.6
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
That leaves every gateway release from 18.1.6 through the 19.1 line inside the affected range.
infrastructure
19.3
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
infrastructure
19.4
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
infrastructure
4.1-ee
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
organisation
Docker
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
infrastructure
19.1
That leaves every gateway release from 18.1.6 through the 19.1 line inside the affected range.
infrastructure
9.9
In February, GitLab
fixed another gateway flaw
, CVE-2026-1868, which it also rated 9.9.
organisation
AI Gateways
GitLab runs AI Gateways for its customers and has already fixed them.
organisation
GitLab.com
Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.
organisation
GitLab Dedicated
Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.
organisation
JWT
A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials.
organisation
HackerOne
GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw.
October 2
GitLab disclosed a critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers, which was subsequently patched with releases 19.2.4, 19.3.2, and 19.4.1.
Click on any entity below to view its context and source!
vulnerability
CVSS score of 9.9
GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
organisation
CVSS
GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
infrastructure
19.3
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
infrastructure
19.4
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
infrastructure
19.2
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
general_metric
19.4 policy
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
general_metric
19.2 policy
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
infrastructure
19.2.4
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
infrastructure
19.3.2
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
infrastructure
19.4.1
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
vulnerability
CVE-2026-90970
GitLab’s October 2 advisory does not say that CVE-2026-90970 has been exploited in the wild.
2026/10/02
Threat actors could potentially exploit a critical vulnerability in GitLab's AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), allowing an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on self-hosted servers under certain conditions.
Click on any entity below to view its context and source!
infrastructure
19.2.4
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.3.2
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.4.1
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
18.1.6
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.2.3
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.3.0
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.3.1
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
infrastructure
19.4.0
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
organisation
CVE-2026-90970
GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
infrastructure
9.9
GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
organisation
GitLab
GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers.
organisation
Vulnerability / Application Security
Swati Khandelwal
Oct 02, 2026
Vulnerability / Application Security
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab
said in an advisory
.
organisation
AI Gateway
Swati Khandelwal
Oct 02, 2026
Vulnerability / Application Security
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab
said in an advisory
.
organisation
AI Gateways
GitLab says the security fix has already been deployed to its own hosted AI Gateways.
organisation
GitLab.com
Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance connected to a GitLab-hosted gateway therefore do not need to take action.
organisation
HackerOne
GitLab credited the HackerOne researcher
invisiblemeerkat
with responsibly reporting the vulnerability.
organisation
The GitLab AI Gateway
The GitLab AI Gateway is basically the middle layer between GitLab Duo and the AI models.
infrastructure
9.8
The flaw, tracked as
CVE-2026-90898
(CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration.
infrastructure
2.1.0
The flaw, tracked as
CVE-2026-90898
(CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration.
organisation
Bifrost
The flaw, tracked as
CVE-2026-90898
(CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration.
organisation
MCP
Yuval Moravchick of
JFrog Security Research
, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client.
organisation
POST
Yuval Moravchick of
JFrog Security Research
, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client.
organisation
API
Yuval Moravchick of
JFrog Security Research
, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client.
organisation
/api/mcp
Yuval Moravchick of
JFrog Security Research
, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client.
organisation
Operators
Operators should upgrade to transports/v2.1.0, which returns 403 when an unauthenticated caller tries to register a stdio MCP client.
organisation
JFrog
JFrog advises treating any instance that ran with authentication disabled and the management API exposed as compromised, and rotating virtual keys and provider API keys.
organisation
Neither Bifrost CVE
Neither Bifrost CVE appears in the KEV catalog as of publication.
organisation
KEV
Neither Bifrost CVE appears in the KEV catalog as of publication.
Tactical Metrics
Metrics
infrastructure
19.2.4
Software Version
Click for context!
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
No fixed version is listed below 19.2.4.
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.3.2
Software Version
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.4.1
Software Version
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
18.1.6
Software Version
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
That leaves every gateway release from 18.1.6 through the 19.1 line inside the affected range.
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.3
Software Version
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
Metrics
infrastructure
19.4
Software Version
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
Metrics
infrastructure
4.1-ee
Software Version
Gateway version in use
First fixed version
18.1.6 or later, before 19.2.4
19.2.4
19.3, before 19.3.2
19.3.2
19.4, before 19.4.1
19.4.1
To
update a Docker deployment
, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee.
Metrics
infrastructure
19.1
Software Version
That leaves every gateway release from 18.1.6 through the 19.1 line inside the affected range.
Metrics
infrastructure
19.2
Software Version
As of October 2, GitLab's
maintenance policy
listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes.
Metrics
infrastructure
9.9
Software Version
In February, GitLab
fixed another gateway flaw
, CVE-2026-1868, which it also rated 9.9.
GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
Metrics
infrastructure
19.2.3
Software Version
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.3.0
Software Version
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.3.1
Software Version
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
19.4.0
Software Version
Below are the affected AI Gateway releases:
Affected version
Fixed version
18.1.6 through 19.2.3
19.2.4
19.3.0 through 19.3.1
19.3.2
19.4.0
19.4.1
The AI Gateway sits between GitLab’s AI features and the underlying models.
Metrics
infrastructure
9.8
Software Version
The flaw, tracked as
CVE-2026-90898
(CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration.
Metrics
infrastructure
2.1.0
Software Version
The flaw, tracked as
CVE-2026-90898
(CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration.
Intelligence Sources
The Hacker News
2026-09-22
The Hacker News
2026-10-02
Security Affairs
2026-10-03
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
CVSS
entity
16x
infrastructure
Software Version
19.2.4
version
9x
timeline
Temporal Reference
Oct 02, 2026
date
5x
vulnerability
Exploited CVE
CVE-2026-90970
cve
3x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
3x
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
2x
general metric
Policy
19
policy
Contextual Telemetry
Context Block
8 METRICS
vulnerability
CVSS Score
10
score
general metric
Line
19
line
general metric
Cve-2026
10
cve-2026
general metric
Oct
2
oct
general metric
Flaw
10
flaw
general metric
Sep
22
sep
general metric
Llm Providers
20
llm providers
general metric
V2.1.0
403
v2.1.0
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.