GitLab told customers on October 2 to patch a critical bug in the self-hosted AI Gateway, CVE-2026-90970. I pulled that from BleepingComputer and the NVD record. A user who already has Duo Agent Platform access can feed a crafted flow configuration, leave the prompt-template sandbox, and run commands on the gateway. Fixes shipped in 19.2.4, 19.3.2, and 19.4.1. If GitLab hosts the gateway for you, they say you are already covered.

CISA had already added a separate GitLab path-traversal bug, CVE-2026-85706, to the Known Exploited Vulnerabilities catalog in September. This one hits people who stood up Duo Self-Hosted so models and source would stay in-house.

The privilege is a logged-in Duo user, not the open internet. That still matters if the gateway box also holds tokens and code. I would update the image and look at who has Duo Agent Platform access before I did anything else.