What Happened
On January 14, 2025, GitLab disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service. An attacker with basic user privileges could execute arbitrary commands on affected systems. GitLab released patches in versions 19.2.4, 19.3.2, and 19.4.1, and directly notified customers running self-hosted instances. Given that GitLab's platform serves over 50% of Fortune 100 companies, the potential impact was significant.
This was not a theoretical vulnerability. The combination of AI service integration and privilege escalation created a direct path from low-privilege access to system-level control.
Timeline
Pre-disclosure: Unknown period where the vulnerability existed in production AI Gateway deployments.
January 14, 2025: GitLab publicly disclosed CVE-2026-90970 and released patched versions across three active release branches.
Same day: GitLab began direct customer notifications for affected self-hosted instances.
Shortly after: CISA acknowledged the vulnerability's significance for organizations running critical infrastructure.
The quick timeline from disclosure to patch availability reflects GitLab's internal detection and response capability. However, it also means your window to patch before public exploit development is narrow.
Which Controls Failed or Were Missing
Input Validation at the API Boundary
The AI Gateway accepted commands from authenticated users without proper sanitization or validation. This is a classic failure: trusting that authentication equals authorization to execute system commands. It doesn't.
Your AI Gateway shouldn't process user input as executable code, regardless of authentication status. The service failed to implement input validation controls that would reject or escape command sequences before processing.
Principle of Least Privilege
A user with "basic privileges" shouldn't have a code path to arbitrary command execution. The service architecture granted excessive permissions to the AI Gateway process itself or failed to properly isolate user contexts. When your AI service runs with elevated privileges and accepts user input, you've created a privilege escalation ladder.
Defense in Depth
No secondary controls caught the command injection attempt. There's no evidence of runtime application self-protection, command execution monitoring, or anomaly detection that would flag unusual system calls from the AI Gateway process. A single control failure led directly to system compromise.
What the Relevant Standard Requires
OWASP ASVS v4.0.3, Requirement 5.3.3: "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters."
While this specifically addresses HTTP parameters, the principle extends to any user-controlled input processed by the application. Your AI Gateway processes user queries and configuration parameters. Each input vector needs validation.
OWASP Top 10 2021, A03:2021, Injection: "An application is vulnerable to attack when user-supplied data is not validated, filtered, or sanitized by the application."
Command injection sits squarely in this category. The vulnerability existed because user input flowed directly into command execution contexts without validation.
NIST 800-53 Rev 5, SI-10 (Information Input Validation): "Check the validity of information inputs." The control requires organizations to verify that information system inputs match defined formats and are within acceptable ranges before processing.
Your AI Gateway should validate every input against an allowlist of expected patterns. If you're accepting natural language queries, you need to parse and validate the intent before passing anything to system-level functions.
ISO/IEC 27001:2022, Control 8.22 (Segregation in networks): While primarily about network segmentation, the principle applies to process isolation. Your AI services should run in isolated contexts with minimal privileges, separate from core system functions.
Lessons and Action Items for Your Team
Inventory Your AI Integration Points
You can't patch what you don't know you're running. Document every AI service, model endpoint, and integration in your environment. For each one, answer:
- What privileges does this service run with?
- What user input does it accept?
- What system resources can it access?
Create a dependency map showing how these AI services connect to your core infrastructure. GitLab's AI Gateway sat at the intersection of user access and system commands. Where do yours sit?
Implement Input Validation for AI Services
Your AI endpoints need the same input validation as any other API. Before processing user queries:
- Define expected input formats and enforce them
- Implement allowlists for command structures
- Escape or reject special characters that could break out of intended contexts
- Log rejected inputs for security monitoring
Don't assume your AI model's natural language processing provides security. It doesn't. Validation happens before the AI sees the input.
Apply Least Privilege to AI Service Accounts
Review the permissions granted to your AI Gateway and similar services. They should run with the minimum privileges needed for their function. If your AI service needs to query a database, it gets read-only access to specific tables. It doesn't need sudo.
Use separate service accounts for each AI integration. When one gets compromised, you've limited the damage to that service's scope.
Monitor AI Service Behavior
Establish baselines for normal AI service activity:
- Volume of requests
- Types of system calls
- Resource access patterns
- Command execution frequency
Alert on deviations. An AI Gateway that suddenly starts executing shell commands or accessing files outside its normal pattern is compromised until proven otherwise.
Test Your Patch Deployment Process
GitLab released patches within hours of disclosure. How fast can you deploy them? Test your emergency patch process for self-hosted services before you need it. You should be able to:
- Identify affected systems within one hour
- Stage and test patches within four hours
- Deploy to production within 24 hours of critical vulnerability disclosure
If you can't hit these timelines, your AI services are sitting ducks during the window between public disclosure and your patch deployment.
Require Security Review for AI Integrations
Before deploying new AI services, run them through the same security review as any other privileged application. This includes:
- Threat modeling the integration points
- Reviewing the service's permissions and access
- Testing input validation and error handling
- Verifying isolation from core systems
AI features don't get a pass on security review just because they're new or experimental. They're often more dangerous because they're less understood.
The GitLab AI Gateway vulnerability demonstrates what happens when AI services integrate with core infrastructure without adequate security controls. Your team can prevent the same outcome by treating AI integrations as the privileged, user-facing attack surface they are.




