{"ok":true,"trend":{"id":814317,"platform":"mastodon","region":"global","key":"🤖 gitlab patches cve-2026-90970 (cvss 9.9, critical) in the ai gateway: a logged-in user with duo agent platform access","title":"🤖 GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access","url":"https://infosec.exchange/@cloud/117374862077165380","first_seen":"2026-10-03T03:58:25.647968Z","last_seen":"2026-10-03T03:58:25.647968Z","last_rank":7,"peak_rank":7,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.93359375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.","why":"A maximum-severity vulnerability in a widely used DevOps platform was just patched, prompting admins to rush updates.","tone":"neutral","entities":["GitLab","AI Gateway","Duo Agent Platform","CVE-2026-90970"],"summarized_at":"2026-10-03T03:59:18.139665Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":901},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"GitLab patches critical AI Gateway flaw allowing command execution","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-03T03:58:25.647968Z","rank":7,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117374862077165380","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access can run commands on the gateway. Only self-hosted gateways affected. Fixed in 19.2.4, 19.3.2, 19.4.1 — update now. 🔗 https:// thehackernews.com/2026/10/gitl…","posted_at":"2026-10-03T03:31:01Z","likes":1}],"elsewhere":[],"window":"7d"}}