Kini o ṣẹlẹ
GitLab released security patches for CVE-2026-90970, a critical vulnerability in its AI Gateway component. The flaw, rated CVSS 9.9, allows authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the host system by exploiting insufficient sanitization of Jinja2-style template placeholders. This is reported as the first critical RCE vulnerability identified in an AI-specific infrastructure component. Self-hosted users must update to versions 19.2.4, 19.3.2, or 19.4.1, while GitLab-hosted instances have already been patched. No evidence of active exploitation or public proof-of-concept exists as of October 3, 2026.
GitLab has released patches for CVE-2026-90970, a critical vulnerability affecting the GitLab AI Gateway. According to forkast.news, the flaw carries a CVSS score of 9.9 and allows an authenticated user with Duo Agent Platform access to achieve arbitrary command execution on the underlying host. The vulnerability is classified under CWE-1336 and stems from insufficient sanitization of user-supplied flow configuration data.
The technical mechanism involves the AI Gateway's use of Jinja2-style template placeholders to process configurations. Because the input is not properly neutralized, an attacker can manipulate the template engine to perform a sandbox escape, breaking out of the intended execution context to execute commands directly on the host operating system. The source notes this is the first critical remote code execution vulnerability identified in an AI-specific infrastructure component.
For organizations operating self-hosted instances, the implications are significant because the AI Gateway acts as a central hub holding sensitive JWT signing keys and managing connections to internal GitLab instances and external AI model providers. GitLab-hosted instances have been patched, but self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1. There is no available workaround, and no reliable method exists to determine whether a gateway was compromised before patching.
The source reports that as of October 3, 2026, there is no evidence of exploitation in the wild and no public proof-of-concept exploit has been published. CISA assessed the exploitation status as none on October 2. However, the source emphasizes that the absence of a known exploit does not reduce the severity for self-hosted environments, making the update the only effective remediation.
Awọn alaye orisun: forkast.news ↗
Kini idi ti o ṣe pataki
This incident highlights a persistent security weakness in infrastructure, specifically the failure to properly isolate template engines from user-controllable inputs. Because the AI Gateway manages sensitive JWT signing keys and connections to external AI model providers, a compromise could grant attackers control over an organization's AI workflows and authentication tokens. The recurrence of this vulnerability class in the same component within eight months underscores the need for robust sandboxing in AI deployment environments.
The vulnerability fits a 'trust-through-defaults' pattern where components are deployed with insufficient security boundaries around user-controllable inputs. The source links this to recent incidents including the OpenAI Misalignment Portal DNS sandbox escape and the DIVD Zammad breach, suggesting a broader trend of security failures in platforms.
The recurrence of this specific vulnerability class is notable. In February 2026, a previous vulnerability (CVE-2026-1868) was identified in the same Duo Workflow Service component, also involving CWE-1336 and carrying a CVSS 9.9 rating. This indicates that the template-engine sandbox boundary remains a persistent point of failure for platforms.
A compromise of the AI Gateway could give an attacker control over an organization’s AI-integrated workflows and authentication tokens. This is particularly concerning because the component manages connections to external AI model providers, potentially exposing sensitive data or enabling lateral movement within an organization's infrastructure.
Ibaraẹnisọrọ Mechanism: Bii O Ṣe Nṣiṣẹ Lootọ
Ṣawari imọ-ẹrọ abẹlẹ lẹhin idagbasoke yii ni ibaraenisọrọ.
crm_get_transaction(id='4092').An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?
Kini lati wo tókàn
Monitor for any public disclosure of proof-of-concept exploits or evidence of in-the-wild exploitation. Track whether other AI infrastructure vendors address similar template-engine sandboxing issues. Observe if CISA or other regulatory bodies issue further guidance on securing platforms.
Security professionals should focus on the template-engine sandbox boundary and the agent capability and tool boundary, which governs how agents interact with external systems. The source suggests that the rate at which AI infrastructure vulnerabilities are being identified is accelerating.
Organizations should verify their patch status immediately, as there is no reliable method to detect prior compromise. The recurrence rate of high-severity vulnerabilities in the same component should drive the timeline for self-hosted operators to apply updates.
Watch for further disclosures from CISA or other security agencies regarding the exploitation status of this vulnerability, as well as any similar vulnerabilities reported in other AI infrastructure components.