A CVE About AI Agent Permissions Made Me Re-Check What Our Own Agent Could Touch
Earlier this month, a critical vulnerability showed up in GitLab's AI Gateway — CVE-2026-90970, CVSS 9.9, letting a logged-in user with agent platform access run commands on the gateway itself. I read the advisory the way most people probably did: nodded, thought "glad that's not us," and moved on. Then I actually thought about our own setup for about ten more seconds, and the "glad that's not us" feeling evaporated. We'd wired an internal AI agent into our infra for the usual reasons — it could read logs, query our internal APIs, open PRs, restart a flaky worker, that kind of thing. It talked
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in