GitLab patches 9.9 RCE in self-hosted AI Gateway (CVE-2026-90970)
CVE-2026-90970, a CVSS 9.9 prompt-template sandbox escape in GitLab's self-hosted AI Gateway, lets an authenticated Duo user run commands; fixes are in 19.2.4, 19.3.2, and 19.4.1.
CVE-2026-90970, a CVSS 9.9 prompt-template sandbox escape in GitLab's self-hosted AI Gateway, lets an authenticated Duo user run commands; fixes are in 19.2.4, 19.3.2, and 19.4.1.