Skip to content
TECH CEO Daily

GitLab AI Gateway vulnerability rated 9.9 as Truffle finds 543,699 live credentials in GitHub code

A critical GitLab Duo gateway bug, live Gemini and cloud keys in public code and malware pushed through a ChatGPT Custom GPT show AI tooling now needs production-grade security.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1GitLab fixed CVE-2026-90970, rated 9.9, which could let some logged-in users run commands on self-hosted AI Gateways.
  • 2Truffle Security found 543,699 credentials in public GitHub code that still worked in July 2026, including 31,374 Gemini keys.
  • 3Huntress tied at least 40 incidents to a malware campaign that used a malicious ChatGPT Custom GPT promoted in Google ads.

The news

GitLab (GTLB) disclosed on October 2 a critical flaw in its self-hosted AI Gateway, rated 9.9 out of 10, that could let some logged-in users run commands on the server. The GitLab AI Gateway vulnerability lands alongside malicious Custom GPTs and 543,699 leaked live credentials.

The AI Gateway gives customers access to GitLab Duo's AI features. According to GitLab's advisory, the bug, tracked as CVE-2026-90970, let an authenticated user with access to the Duo Agent Platform escape the prompt template sandbox with a specially crafted flow configuration and execute arbitrary commands on the gateway. Affected releases run from 18.1.6 up to the fixed versions 19.2.4, 19.3.2 and 19.4.1.

GitLab said it had already deployed a fix for GitLab-hosted gateways, so GitLab.com, GitLab Dedicated and self-managed instances that use a GitLab-hosted gateway are protected. Customers who run their own AI Gateway must upgrade. A researcher using the name invisiblemeerkat reported the issue through HackerOne, and neither GitLab's advisory nor BleepingComputer's report said the flaw had been exploited.

On September 29, Truffle Security said it scanned The Stack v3, a snapshot of 224,553,295 public GitHub repositories assembled to train AI models, and found 543,699 unique credentials that still authenticated when tested in July 2026. The median one had sat in public for 784 days, and the oldest live credential was last touched in June 2009. Google Cloud service accounts made up the largest group at 69,041, followed by 51,067 MongoDB connection strings.

Truffle also counted 31,374 live keys for Google's Gemini models, which it called billable credentials attached to a model endpoint. Revocation varied widely: 1 of 101,886 leaked npm tokens still worked, against 69,041 of 126,963 Google Cloud service accounts. Truffle said 36.8% of the live credentials leaked after GitHub, owned by Microsoft (MSFT), turned on Push Protection by default in February 2024, and 51.8% fell into types that feature does not block by default.

AI assistants are being abused as lures too. Huntress said on September 28 that attackers promoted a Custom GPT named "Plus 5.6" in sponsored Google results; it sent visitors to a fake verification page that told them to paste a command into a terminal on their Windows PC, installing a remote access trojan. Huntress said it responded to at least 40 incidents tied to the campaign's Google Sites domain, two of them confirmed as driven by the Custom GPT, and said OpenAI had removed the first GPT by September 25 before a second appeared by September 27.

The numbers

CVSS score of GitLab's CVE-2026-90970
9.9 (Critical)
Fixed AI Gateway versions
19.2.4, 19.3.2, 19.4.1
Live credentials found in public GitHub code (Truffle)
543,699
Median time a live credential sat in public
784 days
Live Gemini keys found (Truffle)
31,374
Google Cloud service accounts still live, of those leaked
69,041 of 126,963
Incidents Huntress tied to the Custom GPT campaign domain
At least 40

Why CEOs should care

For CISOs and platform teams, the GitLab bug is a reminder that AI gateways are servers, not features. The flaw needed only a logged-in account with Duo Agent Platform access, so a phished developer login could be enough. Put every self-hosted AI component, from gateways to agent platforms and model servers, on the same patch schedule and asset inventory as production systems, limit who can create agent flows, and decide whether the AI team or IT owns those patches.

For CFOs and engineering leaders, Truffle's numbers turn leaked secrets into a budget issue. A live Gemini key is billable, and a live cloud service account can reach company data. Truffle's advice is to assume a credential is compromised the moment it is exposed and rotate it before cleaning up code history. Ask whether keys expire automatically, whether old public repositories and forks are scanned, and whether anyone tracks which providers revoke leaked tokens on their own.

For IT and security awareness teams, the Custom GPT campaign ran through trusted names: a chatgpt.com address, Google ads and a Google Sites page. Blocking bad domains will not stop that. Tell staff that no real AI service asks them to paste commands into a terminal or the Windows Run dialog, restrict the Run dialog where practical, and, as Huntress suggests, alert when PowerShell launches installers from temporary folders.

The bigger picture

Each layer companies add to adopt AI, from gateways and agent platforms to custom assistants and API keys, is software that can be misconfigured, leaked or abused. The Stack v3 itself shows the overlap: a dataset built to train AI models also turned out to hold hundreds of thousands of working keys.

The defenses are familiar: patching, least privilege, short-lived credentials and user training. The difference is ownership. AI tools often arrive through product or data teams rather than IT, and those teams may not run the same patch, monitoring and secrets processes that core systems get.

What’s next

Watch whether exploitation of CVE-2026-90970 is reported once details spread, and how quickly self-hosted GitLab customers upgrade. Also watch whether GitHub widens Push Protection defaults to the credential types Truffle says slip through, and whether OpenAI changes how it reviews Custom GPTs promoted through ads.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

GitLabGitHubTruffle SecurityOpenAISecrets management

Earlier coverage of GitHub

All GitHub coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.