BleepingComputer· Sergiu Gatlan·· 20 小时前AI 评分75
GitLab 修复 AI Gateway 严重 RCE 漏洞
GitLab warns of critical RCE vulnerability in AI Gateway service
AI 导读
GitLab 警告 AI Gateway 存在可导致任意命令执行的严重漏洞 CVE-2026-90970,具备基本权限和 Duo Agent Platform 访问权的攻击者可利用特制流程配置逃逸提示模板沙箱。自托管用户应升级至 19.2.4、19.3.2 或 19.4.1,GitLab 托管的 AI Gateway 已获保护,无需操作。
来源:BleepingComputer · bleepingcomputer.com