GitLab patches RCE flaw in AI Gateway service GitLab patched a critical remote-code-execution flaw, tracked as CVE-2026-90970, in its AI Gateway service that could have let attackers run arbitrary commands on vulnerable instances, including users with basic privileges. GitLab urged users to apply the patch as soon as possible. GitLab has patched a critical remote-code-execution flaw in its AI Gateway service, known as CVE-2026-90970, which could have allowed attackers to run arbitrary commands on vulnerable instances. Even users with basic privileges could exploit this vulnerability, making it essential to apply the patch ASAP.