GitLab has patched a critical vulnerability (CVSS 9.9) in its self-hosted AI gateway that allowed users to escape the prompt template sandbox. The flaw, identified as CVE-2026-90970, could enable malicious actors to execute arbitrary commands by crafting specific flow configurations. The vulnerability affected several versions of GitLab, with fixes released in versions 19.2.4, 19.3.2, and 19.4.1. AI
IMPACT This vulnerability highlights the security risks associated with AI gateway implementations and the need for robust sandboxing.
RANK_REASON The cluster describes a security patch for a specific product feature, not a new release or major industry event.
Read on Mastodon — sigmoid.social →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →