GitLab patches a critical 9.9 AI Gateway flaw that runs commands on self-hosted servers
On October 2, GitLab fixed a critical vulnerability (CVE-2026-90970, CVSS 9.9) that lets a logged-in user execute commands on the AI Gateway, the service that connects a GitLab instance to AI models. Only organizations that host their own gateway need to act: move to 19.2.4, 19.3.2 or 19.4.1 now.