BlackTree Security · Infrastructure · Automation · AI

GitLab’s Self-Hosted AI Gateway Needs an Immediate Update

GitLab urges immediate self-hosted AI Gateway upgrades for CVE-2026-90970. The 9.9 flaw could let an authenticated Duo Agent Platform user escape the prompt template sandbox through a crafted flow and execute arbitrary commands on the gateway.

Affected builds

  • 18.1.6 to <19.2.4: install 19.2.4.
  • 19.3 to <19.3.2: install 19.3.2.
  • 19.4 to <19.4.1: install 19.4.1.

GitLab’s hosted gateway is fixed. GitLab.com, Dedicated and Self-Managed users routed there need no customer gateway patch. Self-Managed users running self-hosted gateways do. GitLab documents both paths.

BlackTree’s advice: identify each Duo feature’s gateway, update affected self-hosted builds, then verify the running version and feature route. A GitLab core update alone is insufficient.

GitLab gives no active-exploitation report; that does not prove none occurred.

Leave a Reply

Your email address will not be published. Required fields are marked *