# GitLab warns of critical RCE vulnerability in AI Gateway service

> **Open Intelligence Dossier** · First detected: 2026-10-04 08:20 UTC · Category: Business

## Executive Summary
GitLab addresses a critical remote code execution flaw in its AI Gateway service.

## Intelligence Brief
Recent reports from outlets including BleepingComputer, The Hacker News, InfoQ, Forkast.news, and contributor Pasquale Pillitteri detail an urgent security development regarding GitLab. Specifically, GitLab has issued patches for a critical remote code execution vulnerability residing within its AI Gateway service. The security flaw, designated with the identifier CVE-2026-90970, carries a severe severity rating of 9.9. According to the available coverage, this vulnerability enables unauthenticated data exfiltration and allows for command execution directly on affected self-hosted servers. Media coverage heavily emphasizes the immediate nature of the threat, noting that the vulnerability is currently under active exploitation.


Outlets such as InfoQ and The Hacker News underscore that the flaw leaves self-hosted environments particularly vulnerable to unauthorized system commands and unauthorized extraction of sensitive data. In response, GitLab has made patches available to remediate CVE-2026-90970. The coordinated reporting across multiple technical publications highlights the widespread concern among system administrators managing instances of the affected AI Gateway service. The context provided by the coverage centers on the integration of artificial intelligence services within enterprise development platforms and the expanded attack surfaces such features introduce. As organizations increasingly deploy self-hosted servers running AI components like the GitLab AI Gateway, vulnerabilities of this magnitude present immediate risks to enterprise infrastructure.


The coverage points to the critical importance of timely patching, especially given that malicious actors are actively exploiting the weakness to target unpatched systems. Future developments will depend on how quickly administrators apply the provided patches across self-hosted server deployments. Coverage does not yet specify the full scope of ongoing attacks or the identity of affected organizations beyond confirming active exploitation. Observers and users of the GitLab AI Gateway service will need to monitor official channels and security advisories from GitLab for further updates regarding CVE-2026-90970 mitigation and remediation verification.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| Pasquale Pillitteri | GitLab patches the 9.9 CVE-2026-90970 vulnerability in its AI Gateway | [Source Link](https://news.google.com/rss/articles/CBMinwFBVV95cUxNNml3UmxjWWdFcWltRlZhdXJXaWdqTTRwNldMcDBvYTh1QXJWTDlNaGR5T2Q3aFBFbHByenptSFJ2VzMtQUlKcHRiRDduZHVDckQ4OXV4dmRPejNTYi1ON0NLNk9XMWoxeGxWbVNKc1NaejJqbTl6Mi1VaWF3OFFESGQ5VDZUeFpua1FldEk3N3pDRnJrZUxOQkpXWlI2ckU?oc=5) |
| forkast.news | GitLab Patches Critical AI Gateway RCE Vulnerability — Prompt Template Sandbox Escape Rated CVSS 9.9 | [Source Link](https://news.google.com/rss/articles/CBMivAFBVV95cUxNZW9kMHV6S09kc2hsaURLRklLMFJ4T1F2a29RMFBTenk3QjBBZ2tPUVpOMTBQX1hXU3V0bENDaG1fSHF4VW5YdTF4VTdJUGsxVUttaTB6cVUwZHZrTHgyTERJWlNkLUdKOHFUZ3pJN2lyd0hZX1RrcWQyUFNMR1AxTnQ4VExuaW9UTVNKb1JoaWNoeTk3LV9xdTEySkR2LUpxMWVuUUZ3TGVzNllpaU05Wkh0MHc3Ql9GNFJ5bw?oc=5) |
| infoq.com | GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration | [Source Link](https://news.google.com/rss/articles/CBMidkFVX3lxTE9BZUF1N2hYa0ZiRGZNSmM4dkFTNml5XzRsenpnZHFlby1lcnQ0R2ZBX1gyQmNNeVBCWEt4V2R6Xzh0STQ3NVhWRUk3VVZzODI4eVhHTTFBbk5JSGhyRXZ4N3NQZ2tzeE11VlJBWFRMYlB2aktTd2c?oc=5) |
| The Hacker News | GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers | [Source Link](https://news.google.com/rss/articles/CBMigwFBVV95cUxNTEtUeFUtb2pFQVluWkNXMGZvZjhjNnluYk85VG1MaXBEZ3pBd0FuTXBXaVZZd1JWcXduWDBiOGgzcjdtSU5peHhqa0NkU1I4UHdJNDlkanpmV1VySFd1bzFPeE1XNXUzQWE1YmdsSjE2ajdGdUJlUFp4c2F0cTVYaVJOdw?oc=5) |
| BleepingComputer | GitLab warns of critical RCE vulnerability in AI Gateway service | [Source Link](https://news.google.com/rss/articles/CBMisgFBVV95cUxNd2xlYjZ2SEYwa29YaGV1akZtRjJrbmNDbEVpY3p3b3BOX3UyMUkxbnQ2TldjWk5zU3VVTkZyVkNIdTlXeWduUTN6SG9aY3EzRi1IZG5OYkVBbGJ3WE5xRHZTdGllTFNGX0EwWlZnNGRCWWR2eHZrZi1oa3YxV1JBZHVIbDFEdThEM29ucUJyNVhRa2EtWnlBNFlXcEtvaGxEV2pzSjFlWXBIMUVkdTRTOVhn0gG3AUFVX3lxTE41aV92SW8xZkhxa2JjNGNnc1dTSmJpVlViVmVST0FPVEI4Nm5BV0dGMjlKeExIYUR4dlBkT19qZmF0LWk4SEl2bWpKOE82dVZvOWZSWFFTcTdKbG5YMWNLa3lkWFpWaXVlQS0xOTN3NDdYWExndXFVS2doZnBPZkg0TUJaQ1R3Vy1aeFRqZzdhYThHLVNBYkxNem9uZ1VFa2x) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-10-04/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service*
