GitLab AI Gateway Critical RCE: What Self-Managed Teams Need to Do Now
What happened
GitLab warned of a critical vulnerability in AI Gateway tracked as CVE-2026-90970. Under certain conditions, a logged-in user with Duo Agent Platform access could execute commands on a vulnerable self-hosted gateway.
Who is affected
Organizations that run self-managed GitLab environments and host their own AI Gateway are in scope. GitLab-hosted gateway users were reported as already remediated by GitLab.
Why it matters
AI integration points are now part of the production attack surface. A compromise at the gateway layer can impact confidentiality of prompts and outputs, service integrity, and potentially downstream development workflows.
Technical details
- CVE: CVE-2026-90970
- Severity: Critical (publicly reported as CVSS 9.9)
- Exposure: Self-hosted AI Gateway deployments
- Exploitation status: No broad exploitation campaign publicly confirmed at publication time
- Fixed versions: Public reports indicate patched AI Gateway releases were issued on October 2, 2026
Recommended actions
- Upgrade AI Gateway to vendor-fixed releases immediately.
- Inventory all GitLab AI integrations and confirm whether any environment is self-hosting the gateway.
- Restrict access to Duo Agent Platform features to least privilege.
- Review gateway, auth, and API logs for unusual command execution or anomalous request patterns.
- Add temporary compensating controls such as network segmentation and stricter allowlists around gateway hosts until patching is complete.
Sources
- https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
- https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
