VulnerabilitiesGitLab patches a near-perfect-score AI Gateway bug that lets logged-in users run commands on the server
CVE-2026-90970 scores 9.9 out of 10 and lets any authenticated user with Duo Agent Platform access escape a prompt template and execute code. Only self-hosted gateways need the fix.