Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

GitLab AI Gateway Flaw CVE-2026-90970 Scores 9.9: What Canadian DevOps Teams Should Check

What Happened

GitLab fixed a critical flaw in its self-hosted AI Gateway. BleepingComputer reports CVE-2026-90970 carries a CVSS score of 9.9. An authenticated user with Duo Agent Platform access escapes the prompt template sandbox through a crafted flow configuration. The attacker then runs commands on the gateway.

The flaw affects gateway versions 18.1.6 through 19.1.x, plus 19.2.x before 19.2.4, 19.3.x before 19.3.2, and 19.4.x before 19.4.1. GitLab.com, Dedicated, and other managed instances are already patched. GitLab reports no exploitation. A HackerOne researcher found the issue.

Why This Matters for Canadian Organizations

The AI Gateway connects your GitLab instance to AI models, and it holds JWT signing keys. Command execution there gives an attacker a path to forge tokens and move toward source code and pipelines. Source repositories hold secrets, infrastructure code, and customer data logic.

Canadian banks, public sector bodies, and defence suppliers often self-host GitLab to keep code in-country. This choice puts patching on your shoulders. The same pattern appeared in our coverage of AI infrastructure flaws, where tools built to speed development gain deep trust and weak isolation. Regulated firms under OSFI technology risk guidance should log this as a critical third-party software issue and track the fix to closure.

Attackers need valid credentials and platform access, which lowers urgency slightly for locked-down teams. It does not remove it. Phished developer accounts are common.

What to Do

Inventory every self-hosted AI Gateway. Upgrade to 19.2.4, 19.3.2, or 19.4.1. Review who holds Duo Agent Platform access and remove unused accounts. Rotate JWT signing keys if you suspect misuse. Watch gateway hosts for unexpected child processes and outbound connections. Read the October 2 daily brief for the day’s other critical patches.

Enjoy this article? Don’t forget to share.