First reported secmate.dev
Lead dispatch
First reported · updated · 2 reports bleepingcomputer.com
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab patched CVE-2026-90970, a critical (CVSS 9.9) flaw in its self-hosted AI Gateway service powering GitLab Duo features. An authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway. Fixes shipped in versions 19.2.4, 19.3.2, and 19.4.1; GitLab-hosted instances are already protected.sandbox-escape · remote-code-execution · prompt-injection · tool-abuse
ai-gateway · llm · gitlab-duo · ai-agents
Severity
0.82
How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector