返回新聞
安全性AI Understanding 簡報

亞搏體育appGitLab修復了關鍵的AI網關RCE漏洞

GitLab 發布了 CVE-2026-90970 的補丁,這是其 AI 網關中的關鍵遠端程式碼執行缺陷,允許透過模板注入逃逸沙箱。

4 min readRead the linked source
Source-provided image accompanying GitLab patches critical AI Gateway RCE vulnerability
來源參考來源記錄
出版商
forkast.news
來源連結
forkast.newshttps://forkast.news/gitlab-patches-critical-ai-gateway-rce-vulnerability-prompt-template-sandbox-escape-rated-cvss-9-9/
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

人工智慧代理
一種可以觀察、推理並採取行動來實現目標的軟體系統,通常使用工具和記憶體。
測試一下自己AI 代理測驗

發生了什麼事

GitLab released security patches for CVE-2026-90970, a critical vulnerability in its AI Gateway component. The flaw, rated CVSS 9.9, allows authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the host system by exploiting insufficient sanitization of Jinja2-style template placeholders. This is reported as the first critical RCE vulnerability identified in an AI-specific infrastructure component. Self-hosted users must update to versions 19.2.4, 19.3.2, or 19.4.1, while GitLab-hosted instances have already been patched. No evidence of active exploitation or public proof-of-concept exists as of October 3, 2026.

GitLab has released patches for CVE-2026-90970, a critical vulnerability affecting the GitLab AI Gateway. According to forkast.news, the flaw carries a CVSS score of 9.9 and allows an authenticated user with Duo Agent Platform access to achieve arbitrary command execution on the underlying host. The vulnerability is classified under CWE-1336 and stems from insufficient sanitization of user-supplied flow configuration data.

The technical mechanism involves the AI Gateway's use of Jinja2-style template placeholders to process configurations. Because the input is not properly neutralized, an attacker can manipulate the template engine to perform a sandbox escape, breaking out of the intended execution context to execute commands directly on the host operating system. The source notes this is the first critical remote code execution vulnerability identified in an AI-specific infrastructure component.

For organizations operating self-hosted instances, the implications are significant because the AI Gateway acts as a central hub holding sensitive JWT signing keys and managing connections to internal GitLab instances and external AI model providers. GitLab-hosted instances have been patched, but self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1. There is no available workaround, and no reliable method exists to determine whether a gateway was compromised before patching.

The source reports that as of October 3, 2026, there is no evidence of exploitation in the wild and no public proof-of-concept exploit has been published. CISA assessed the exploitation status as none on October 2. However, the source emphasizes that the absence of a known exploit does not reduce the severity for self-hosted environments, making the update the only effective remediation.

來源詳情: forkast.news ↗

為什麼這很重要

This incident highlights a persistent security weakness in infrastructure, specifically the failure to properly isolate template engines from user-controllable inputs. Because the AI Gateway manages sensitive JWT signing keys and connections to external AI model providers, a compromise could grant attackers control over an organization's AI workflows and authentication tokens. The recurrence of this vulnerability class in the same component within eight months underscores the need for robust sandboxing in AI deployment environments.

The vulnerability fits a 'trust-through-defaults' pattern where components are deployed with insufficient security boundaries around user-controllable inputs. The source links this to recent incidents including the OpenAI Misalignment Portal DNS sandbox escape and the DIVD Zammad breach, suggesting a broader trend of security failures in platforms.

The recurrence of this specific vulnerability class is notable. In February 2026, a previous vulnerability (CVE-2026-1868) was identified in the same Duo Workflow Service component, also involving CWE-1336 and carrying a CVSS 9.9 rating. This indicates that the template-engine sandbox boundary remains a persistent point of failure for platforms.

A compromise of the AI Gateway could give an attacker control over an organization’s AI-integrated workflows and authentication tokens. This is particularly concerning because the component manages connections to external AI model providers, potentially exposing sensitive data or enabling lateral movement within an organization's infrastructure.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下來看什麼

Monitor for any public disclosure of proof-of-concept exploits or evidence of in-the-wild exploitation. Track whether other AI infrastructure vendors address similar template-engine sandboxing issues. Observe if CISA or other regulatory bodies issue further guidance on securing platforms.

Security professionals should focus on the template-engine sandbox boundary and the agent capability and tool boundary, which governs how agents interact with external systems. The source suggests that the rate at which AI infrastructure vulnerabilities are being identified is accelerating.

Organizations should verify their patch status immediately, as there is no reliable method to detect prior compromise. The recurrence rate of high-severity vulnerabilities in the same component should drive the timeline for self-hosted operators to apply updates.

Watch for further disclosures from CISA or other security agencies regarding the exploitation status of this vulnerability, as well as any similar vulnerabilities reported in other AI infrastructure components.

相關指引和測驗

人工智慧代理AI 倫理人工智慧模型解釋測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?