MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #7

GitLab patches critical AI Gateway flaw allowing command execution

Original: 🤖 GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access

GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.

Why now: A maximum-severity vulnerability in a widely used DevOps platform was just patched, prompting admins to rush updates.

GitLabAI GatewayDuo Agent PlatformCVE-2026-90970

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/814317