GitLab has fixed CVE-2026-90970, described as a critical 9.9 flaw in AI Gateway that could allow logged-in Duo Agent Platform users to run commands on self-hosted gateways. Administrators should identify exposed self-managed deployments, apply the relevant GitLab update, and review gateway logs for unexpected command activity.
Source: The Hacker News
This report is based on the cited source. Organizations should consult vendor guidance and their own telemetry before acting.
