NewsGitLab AI Gateway CVE-2026-1868 CVSS 9.9 RCEGitLab Security Advisory·high signalXBlueskyLinkedInCopy linkHighest-CVSS AI agent platform vulnerability. Template injection in Duo Workflow enables RCE via agent flow definitions.SourceSource pageGitLab Security Advisory↳ Follow the threadStack layer / Threat patternGitLab's Duo Agent Platform Could Redirect Model Requests to an Attacker-Controlled Endpoint (CVE-2026-19889 / CVE-2026-75871, 8.2)NVDStack layer / Threat patternAgno Turns Prompt Injection Straight Into RCE via PythonTools and ShellTools (CVE-2026-37003)NVDPolicy dependency / Threat patternFraming an exfiltration as an 'integrity signature' takes gpt-4o from 0% to 100% injection successarXivStack layer / Threat patternA contract-centered architecture names Skill, Harness and Scaffold as the ownership boundaries of an agentic runtimearXivStack layer / Follow-up threadLing 3.0 Flash Fin, a 256K-context finance model, is free on Vercel AI Gateway until September 25Vercel ChangelogStack layer / Threat patternTalos Sells a Deterministic Permission Kernel Around Claude and Ships 2,242 Tests as the ProofTalos (Show HN, 2026-08-28)Policy dependency / Stack layerLMSM Ports the Linux Security Modules Split to LLM Serving, Cutting HarmBench ASR 39.20% to 3.32% at 98.14% ThroughputarXiv 2608.25697Policy dependency / Stack layerECC has 243,870 stars and 36,883 forks but has not tagged a release in a month despite pushing dailyGitHub