5 min read
GitLab AI Gateway sandbox escape: what pentest actually catches
CVE-2026-90970 let an authenticated user run commands on GitLab's AI Gateway. The model was not the problem. The boundary was.
- #AI
- #Pentest
- #APIs
CVE-2026-90970 let an authenticated user run commands on GitLab's AI Gateway. The model was not the problem. The boundary was.