
🚨 GITLAB CRITICAL — SELF-HOSTED AI GATEWAY RCE (CVE-2026-90970, CVSS 9.9) GitLab released Critical AI Gateway patch versions 19.2.4, 19.3.2, and 19.4.1 for a Critical security fix affecting GitLab Self-Hosted AI Gateway. • CVE-2026-90970 — Improper neutralization in custom flow prompt templates • Impact: authenticated Duo Agent Platform user can escape the prompt-template sandbox and run arbitrary commands on the AI Gateway • CVSS 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) • Impacted: AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 • http://GitLab.com, Dedicated, and Self-Managed using a GitLab-hosted AI Gateway are already protected — no action • Self-Hosted AI Gateway customers: upgrade immediately to 19.2.4 / 19.3.2 / 19.4.1 ⚠️ Analyst Note: Official GitLab Critical patch for Self-Hosted AI Gateway only — not a dark-web leak claim and not in CISA KEV as of this check. Requires an authenticated user with Duo Agent Platform access; not unauthenticated RCE. No in-the-wild exploitation claimed in the vendor notes reviewed here. Credit: invisiblemeerkat (responsible disclosure). Distinct from the Sep 23 GitLab CE/EE Critical regex RCE patch already covered on @DailyDarkWeb. Primary: https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/ #DDW #DarkWeb #GitLab #CVE202690970 #RCE #AIGateway #ThreatIntelligence #CyberSecurity


















