← Back to the CVE Tracker
GitLab has released patches for a critical vulnerability in its AI Gateway, identified as CVE-2026-90970, which could enable an authenticated user to execute arbitrary commands on self-hosted gateway instances. The flaw, which carries a CVSS score of 9.9, was publicly disclosed by GitLab on October 2, 2026.