HaiAI123

Curated Global AI Tools Directory

NewHot story
97
heat index
New

GitLab AI Gateway Flaw Scores 9.9 CVSS

10/03/2026 — 10/03, 19:11·1 sources·1 reports

Story overview

On October 3, 2026, DEV Community published a report saying GitLab had issued emergency security releases to fix a critical vulnerability affecting self-hosted deployments of its AI Gateway. The vulnerability is tracked as CVE-2026-90970 and carries a CVSS v3.1 score of 9.9, which the report flags in its headline as a command execution risk.

According to the report, the flaw stems from improper neutralization of special elements used in template engines, a weakness it maps to CWE-1336. As a result, administrators or other authorized users who customize prompt flow templates face a command execution risk. The writeup, which includes a technical vulnerability analysis section, describes the exposure as specific to self-hosted installations of AI Gateway, and it characterizes GitLab's response as an emergency security release.

The recommendation given to readers is straightforward: teams running a self-hosted AI Gateway should upgrade as soon as possible. The report does not specify which versions contain the fix, does not state whether the vulnerability has been exploited, and does not say who discovered or reported it. It gives no date for when the vulnerable code was introduced or when the fix shipped, and it offers no statement from GitLab beyond the fact that emergency releases were made available. As of this report, that is the extent of what is known: a 9.9-rated command execution flaw in self-hosted AI Gateway, a CWE-1336 root cause tied to prompt flow templates, and a call to patch.

AI-generated from 1 reports · updated 2 hours ago

Latest turnGitLab has shipped emergency security releases for CVE-2026-90970, a critical flaw (CVSS 9.9) in self-hosted deployments of its AI Gateway. The bug stems from improper neutralization of special elements in template engines (CWE-1336), creating a command execution risk when admins or authorized users define custom prompt flow templates. Self-hosted teams should patch promptly.

Reports on this story headlines open the original

Today
  1. GitLab has shipped emergency security releases for CVE-2026-90970, a critical flaw (CVSS 9.9) in self-hosted deployments of its AI Gateway. The bug stems from improper neutralization of special elements in template engines (CWE-1336), creating a command execution risk when admins or authorized users define custom prompt flow templates. Self-hosted teams should patch promptly.

    DEV Community · AIAI score 82

Other stories people are talking about

How is heat calculated?About the method

Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.

This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source.

Surge
Discussion rising fast
New
First report within 6 hours
Rising
Still gathering discussion

Back to the hot board →