search
Duo Agent Platform
Trends
- 1GitLab warns of critical RCE flaw in AI Gateway▼⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service GitLab disclosed CVE-2026-90970, a critica
GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service. The flaw allows authenticated users with Duo Agent Platform access to escape the prompt sandbox and execute arbitrary commands. Self-hosted instances are affected, and security teams are being urged to patch promptly.
- 2GitLab patches critical AI Gateway flaw allowing command execution●🤖 GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access
GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.