{"ok":true,"trend":{"id":864419,"platform":"mastodon","region":"global","key":"🚨 gitlab ai gateway vulnerability: cve-2026-90970 gitlab has patched a critical **cvss 9.9** vulnerability in its ai gat","title":"🚨 GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI Gat","url":"https://infosec.exchange/@thecybersecguru/117377227975289745","first_seen":"2026-10-03T13:33:53.253529Z","last_seen":"2026-10-03T13:33:53.253529Z","last_rank":8,"peak_rank":8,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.89109375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.","why":"A near-maximum severity flaw enabling remote command execution on self-hosted GitLab deployments has just been patched, prompting urgent warnings to administrators.","tone":"neutral","entities":["GitLab","CVE-2026-90970","AI Gateway"],"summarized_at":"2026-10-03T13:35:19.656335Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1124},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"GitLab patches critical CVSS 9.9 AI Gateway vulnerability","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-03T13:33:53.253529Z","rank":8,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@thecybersecguru/117377227975289745","author":"thecybersecguru@infosec.exchange","title":null,"snippet":"🚨 GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI Gateway that can allow an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Affected: •…","posted_at":"2026-10-03T13:32:42Z","likes":1}],"elsewhere":[],"window":"7d"}}