GitLab patches critical CVSS 9.9 command execution flaw in self-hosted AI Gateway
GitLab has fixed CVE-2026-90970, a critical flaw in its self-hosted AI Gateway that lets authenticated Duo Agent Platform users escape a prompt template sandbox and run commands.
