Post
securityrss.ai
securityrss.bsky.social
did:plc:geidqukzen75knciqkq77vgq
A critical vulnerability in GitLab's AI Gateway, tracked as CVE-2026-90970, allows logged-in users with Duo Agent Platform access to execute commands on self-hosted servers. GitLab rated the flaw 9.9/10 and released fixes in versions 19.2.4, 19.3.2, and 19.4.1 on October 2.
https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
2026-10-03T17:17:11.757Z