Remote Code Execution Vulnerability in GitLab AI Gateway
A critical remote code execution vulnerability (CVE-2026-90970) in GitLab AI Gateway allows unauthenticated attackers to execute arbitrary code on affected installations.
CVE search metadata
CVE search record: CVE-2026-90970. Severity: critical. CVSS: 9.9. EPSS: 0.94%. KEV: no. Product: AI Gateway (19.3.x < 19.3.2), AI Gateway (19.4.x < 19.4.1), AI Gateway (>= 18.1.6 and < 19.2.4). Brief: Remote Code Execution Vulnerability in GitLab AI Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gitlab-rce/
A vulnerability identified as CVE-2026-90970 affects multiple versions of the GitLab AI Gateway. This flaw allows an unauthenticated remote attacker to achieve arbitrary code execution on the underlying host. The vulnerability is present in versions 19.3.x prior to 19.3.2, versions 19.4.x prior to 19.4.1, and versions 18.1.6 through 19.2.4. GitLab released security patches on October 2, 2026, to address this flaw. Organizations running AI Gateway components should prioritize patching to the latest safe versions to mitigate the risk of full system compromise.
Impact
Successful exploitation allows an unauthenticated attacker to gain remote code execution capabilities on the GitLab AI Gateway server. This can lead to complete system takeover, unauthorized access to sensitive data processed by the AI Gateway, or lateral movement within the network environment.
Recommendation
Prioritize patching all affected GitLab AI Gateway instances to the versions specified in the official GitLab security bulletin. Ensure that internet-facing instances are monitored for anomalous outbound traffic or unexpected child process execution from the AI Gateway service account.
Immediate actions
Patch AI Gateway to 19.2.4 or later
Mitigations
Upgrade AI Gateway to 19.2.4 or later
CVE-2026-90970