{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ai-gateway-19.4.x--19.4.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitlab:ai_gateway:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-90970"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AI Gateway (19.3.x \u003c 19.3.2)","AI Gateway (19.4.x \u003c 19.4.1)","AI Gateway (\u003e= 18.1.6 and \u003c 19.2.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","webserver","gitlab"],"_cs_type":"advisory","_cs_vendors":["GitLab"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-90970 affects multiple versions of the GitLab AI Gateway. This flaw allows an unauthenticated remote attacker to achieve arbitrary code execution on the underlying host. The vulnerability is present in versions 19.3.x prior to 19.3.2, versions 19.4.x prior to 19.4.1, and versions 18.1.6 through 19.2.4. GitLab released security patches on October 2, 2026, to address this flaw. Organizations running AI Gateway components should prioritize patching to the latest safe versions to mitigate the risk of full system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to gain remote code execution capabilities on the GitLab AI Gateway server. This can lead to complete system takeover, unauthorized access to sensitive data processed by the AI Gateway, or lateral movement within the network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all affected GitLab AI Gateway instances to the versions specified in the official GitLab security bulletin. Ensure that internet-facing instances are monitored for anomalous outbound traffic or unexpected child process execution from the AI Gateway service account.\u003c/p\u003e\n","date_modified":"2026-10-05T18:41:35Z","date_published":"2026-10-05T18:41:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gitlab-rce/","summary":"A critical remote code execution vulnerability (CVE-2026-90970) in GitLab AI Gateway allows unauthenticated attackers to execute arbitrary code on affected installations.","title":"Remote Code Execution Vulnerability in GitLab AI Gateway","url":"https://feed.craftedsignal.io/briefs/2026-10-gitlab-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - AI Gateway (19.4.x \u003c 19.4.1)","version":"https://jsonfeed.org/version/1.1"}