GitLab Fixes critical vulnerabilities in AI gateway, RCE; CVSS rating
2026-10-03 15:41:22
CoinMeta Data: GitLab has released a patch for CVE-2026-90970, fixing a critical vulnerability that affected its AI gateway. This vulnerability has a CVSS score of 9.9, allowing authenticated users with access to the Duo Agent platform to execute arbitrary commands on the underlying host. This is the first critical remote code execution vulnerability discovered in a specific infrastructure component of AI. The vulnerability stems from inadequate cleaning of user-provided stream configuration data; the AI gateway uses Jinja2-style template placeholders to process this configuration. Since the input was not properly neutralized, attackers could manipulate the template engine to perform sandbox escape. GitLab has been fixed for managed instances, but self-managed users must manually update to versions 19.2.4, 19.3.2, or 19.4.1.
Source:Forkast
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated

Hot Articles
Refresh

Bitcoin October 2026 Outlook: Can the 19% Historical Gain Hold?
09-30 12:57

Dogecoin Price: Whales Buy $112M, Can DOGE Break $0.10?
09-29 12:48

What is Solidigm? Is Its $150B IPO Valuation a Bubble?
09-28 13:00

Is PAXG Stable? Is Gold-Backed Better Than Stablecoins?
09-24 18:04

ETH Rebounds to $2,800: Can It Hold $3,200 by Month-End?
09-23 11:07



