The news
GitLab (GTLB) disclosed on October 2 a critical flaw in its self-hosted AI Gateway, rated 9.9 out of 10, that could let some logged-in users run commands on the server. The GitLab AI Gateway vulnerability lands alongside malicious Custom GPTs and 543,699 leaked live credentials.
The AI Gateway gives customers access to GitLab Duo's AI features. According to GitLab's advisory, the bug, tracked as CVE-2026-90970, let an authenticated user with access to the Duo Agent Platform escape the prompt template sandbox with a specially crafted flow configuration and execute arbitrary commands on the gateway. Affected releases run from 18.1.6 up to the fixed versions 19.2.4, 19.3.2 and 19.4.1.
GitLab said it had already deployed a fix for GitLab-hosted gateways, so GitLab.com, GitLab Dedicated and self-managed instances that use a GitLab-hosted gateway are protected. Customers who run their own AI Gateway must upgrade. A researcher using the name invisiblemeerkat reported the issue through HackerOne, and neither GitLab's advisory nor BleepingComputer's report said the flaw had been exploited.
On September 29, Truffle Security said it scanned The Stack v3, a snapshot of 224,553,295 public GitHub repositories assembled to train AI models, and found 543,699 unique credentials that still authenticated when tested in July 2026. The median one had sat in public for 784 days, and the oldest live credential was last touched in June 2009. Google Cloud service accounts made up the largest group at 69,041, followed by 51,067 MongoDB connection strings.
Truffle also counted 31,374 live keys for Google's Gemini models, which it called billable credentials attached to a model endpoint. Revocation varied widely: 1 of 101,886 leaked npm tokens still worked, against 69,041 of 126,963 Google Cloud service accounts. Truffle said 36.8% of the live credentials leaked after GitHub, owned by Microsoft (MSFT), turned on Push Protection by default in February 2024, and 51.8% fell into types that feature does not block by default.
AI assistants are being abused as lures too. Huntress said on September 28 that attackers promoted a Custom GPT named "Plus 5.6" in sponsored Google results; it sent visitors to a fake verification page that told them to paste a command into a terminal on their Windows PC, installing a remote access trojan. Huntress said it responded to at least 40 incidents tied to the campaign's Google Sites domain, two of them confirmed as driven by the Custom GPT, and said OpenAI had removed the first GPT by September 25 before a second appeared by September 27.
The numbers
- CVSS score of GitLab's CVE-2026-90970
- 9.9 (Critical)
- Fixed AI Gateway versions
- 19.2.4, 19.3.2, 19.4.1
- Live credentials found in public GitHub code (Truffle)
- 543,699
- Median time a live credential sat in public
- 784 days
- Live Gemini keys found (Truffle)
- 31,374
- Google Cloud service accounts still live, of those leaked
- 69,041 of 126,963
- Incidents Huntress tied to the Custom GPT campaign domain
- At least 40
Why CEOs should care
For CISOs and platform teams, the GitLab bug is a reminder that AI gateways are servers, not features. The flaw needed only a logged-in account with Duo Agent Platform access, so a phished developer login could be enough. Put every self-hosted AI component, from gateways to agent platforms and model servers, on the same patch schedule and asset inventory as production systems, limit who can create agent flows, and decide whether the AI team or IT owns those patches.
For CFOs and engineering leaders, Truffle's numbers turn leaked secrets into a budget issue. A live Gemini key is billable, and a live cloud service account can reach company data. Truffle's advice is to assume a credential is compromised the moment it is exposed and rotate it before cleaning up code history. Ask whether keys expire automatically, whether old public repositories and forks are scanned, and whether anyone tracks which providers revoke leaked tokens on their own.
For IT and security awareness teams, the Custom GPT campaign ran through trusted names: a chatgpt.com address, Google ads and a Google Sites page. Blocking bad domains will not stop that. Tell staff that no real AI service asks them to paste commands into a terminal or the Windows Run dialog, restrict the Run dialog where practical, and, as Huntress suggests, alert when PowerShell launches installers from temporary folders.
The bigger picture
Each layer companies add to adopt AI, from gateways and agent platforms to custom assistants and API keys, is software that can be misconfigured, leaked or abused. The Stack v3 itself shows the overlap: a dataset built to train AI models also turned out to hold hundreds of thousands of working keys.
The defenses are familiar: patching, least privilege, short-lived credentials and user training. The difference is ownership. AI tools often arrive through product or data teams rather than IT, and those teams may not run the same patch, monitoring and secrets processes that core systems get.
What’s next
Watch whether exploitation of CVE-2026-90970 is reported once details spread, and how quickly self-hosted GitLab customers upgrade. Also watch whether GitHub widens Push Protection defaults to the credential types Truffle says slip through, and whether OpenAI changes how it reviews Custom GPTs promoted through ads.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









