What’s trending in AI on 3 October 2026: the most dangerous AI news of the day was not a new model. It was three security advisories, published within hours of each other on 2 October, for the software that connects AI to everything else. GitLab patched a CVSS 9.9 flaw in its self-hosted AI Gateway that lets a logged-in user break out of a prompt-template sandbox and run commands on the server. AWS disclosed a perfect CVSS 10.0 authentication bypass in Loom for AWS, its open-source AI agent orchestration platform, where a deployment without an identity provider handed super-admin rights to anyone who could reach it. And AWS fixed a command-injection bug in SageMaker Unified Studio that could let one project member pick up another member’s temporary cloud credentials. Different vendors, one lesson: the gateways and orchestrators that broker your AI models, tools and keys are now the most valuable target in the stack. This guide explains what each flaw does, who is exposed, why the pattern matters, and an if-this-then-that triage list you can work through this weekend.
Key takeaways
- Loom for AWS (CVE-2026-103956, CVSS 10.0): before version 1.6.1, a deployment with no identity provider configured gave any network client full admin control of the agent control plane. Upgrade to 1.7.0, which also fixes two token-leak and internal-network flaws.
- GitLab AI Gateway (CVE-2026-90970, CVSS 9.9): any authenticated user with Duo Agent Platform access could escape the prompt-template sandbox with a crafted flow and run commands. Self-hosted gateways need 19.2.4, 19.3.2 or 19.4.1; GitLab.com and Dedicated are already fixed.
- SageMaker Unified Studio (CVE-2026-104019): a contributor could run code in another member’s Space and, with Trusted Identity Propagation on, use their temporary credentials. Restarting Spaces pulls the patched image.
- No exploitation has been reported for any of them so far, but attackers now turn fresh flaws into exploits in hours, not weeks.
- The pattern is old bugs in a new, richer place: missing authentication, template injection, server-side request forgery and command injection, sitting on top of model keys, OAuth tokens and cloud roles.
- For your business: treat any AI gateway or agent orchestrator like an identity provider. Inventory it, patch it first, put it behind single sign-on, and rotate every secret it can touch after a critical flaw.
1. What was disclosed on 2 October
Loom for AWS. Loom is an open-source platform from AWS Labs, introduced in July, for building and running AI agents on Amazon Bedrock AgentCore with a single management console and API. It manages agents, their memory, the MCP tool servers they call, agent-to-agent connections and the access rules around them. AWS security bulletin 2026-124 lists three problems. The headline one, CVE-2026-103956, is a missing-authentication bug: when no identity provider was configured, the platform defaulted to an insecure state in which unauthenticated requests were treated as super-admin. An attacker could register malicious tool servers, read stored integration credentials and change the IAM policies attached to managed agents. It is scored 10.0, the maximum. Two lesser flaws, fixed in version 1.7.0, let users with write permissions for MCP or agent-to-agent settings point the platform at a malicious OAuth discovery URL that would hand over client secrets or another user’s token (CVE-2026-103957, scored 6.2), or make it connect to internal network addresses and read the responses (CVE-2026-103958, 7.6). The issues were reported by researcher Kenneth Cox.
GitLab AI Gateway. GitLab’s AI Gateway is the service that sits between a GitLab instance and the AI models behind its Duo features, including the Duo Agent Platform’s customizable “flows”. CVE-2026-90970 is a template-injection flaw in the prompt templates of custom flows. A user who is logged in and has Duo Agent Platform access can craft a flow configuration that escapes the template sandbox and runs arbitrary commands on the gateway host. The low privileges required, network access and no user interaction add up to a 9.9 score. It affects self-hosted gateways from 18.1.6 up to the fixed releases 19.2.4, 19.3.2 and 19.4.1. GitLab says there is no workaround and offers no way to check whether the flaw was abused before patching. It was reported through HackerOne by a researcher using the handle invisiblemeerkat.
SageMaker Unified Studio. AWS bulletin 2026-125 covers CVE-2026-104019, an OS command injection in the startup script of SageMaker Studio Spaces. When a Space starts, it validates network access against every SageMaker connection in the project, and connection details were not properly sanitized. A project member with contributor rights could therefore run code in another member’s Space. Where Trusted Identity Propagation is enabled, that becomes a way to borrow the other person’s temporary execution-role credentials and call AWS services as them. AWS has not published a score.
| Product | CVE and score | Who is exposed | Fixed in |
|---|---|---|---|
| Loom for AWS | CVE-2026-103956 (10.0) | Deployments before 1.6.1 running without an identity provider | 1.6.1 (4 Aug 2026); upgrade to 1.7.0 |
| Loom for AWS | CVE-2026-103957 (6.2), CVE-2026-103958 (7.6) | Versions before 1.7.0; needs a user with MCP or agent-to-agent write scope | 1.7.0 |
| GitLab AI Gateway (self-hosted) | CVE-2026-90970 (9.9) | 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0; any user with Duo Agent Platform access | 19.2.4, 19.3.2, 19.4.1 |
| SageMaker Unified Studio / Distribution | CVE-2026-104019 (no score published) | Project contributors on affected image versions; worse with Trusted Identity Propagation | 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, 4.4.3 (restart Spaces); 4.5.x not affected |
2. Why the control plane is the crown jewel
A year ago most companies used AI through a chat window. Today a growing share route it through middleware: an AI gateway that holds the model API keys and decides which model answers which request, or an agent orchestrator that registers tools, stores OAuth tokens for the SaaS apps agents act in, and assigns cloud permissions. That layer is convenient because it centralizes everything. It is dangerous for exactly the same reason.
Think about what the Loom bug offered. Admin rights on an orchestrator are not just access to one app. They let an attacker add a tool server of their choosing, so every agent that trusts the platform starts calling attacker code. They expose the stored credentials for every integration. And they let the attacker rewrite the IAM policies attached to agents, turning a helpful assistant into an account with whatever reach the attacker wants. The GitLab flaw is similar in shape: a gateway that brokers Duo requests sits next to model credentials and your source code workflows, and command execution on that host is a foothold in the software supply chain. We’ve seen what happens when agent tooling becomes the path in, from the “read-only” agents in the SwarmTraces Hugging Face incident to the identity sprawl we flagged when AI agents started getting employee IDs.
There’s also a people problem. Orchestrators and gateways are often stood up by an AI or data team moving fast, not by the infrastructure group that patches the VPN. An open-source agent platform launched in a lab repository in July can be running on a team’s AWS account by August with nobody in security aware of it. That is shadow AI at the infrastructure level, and it’s where an unauthenticated admin API can sit unnoticed.
3. Old bugs in a new place
None of these flaws needs AI to exploit. Look at the weakness categories: missing authentication for a critical function and insecure default initialization (Loom), improper neutralization in a template engine (GitLab), server-side request forgery (Loom) and OS command injection (SageMaker). These are classics that web application security has fought for two decades. What’s new is where they sit.
- Insecure defaults are back. Loom’s worst bug only bites when no identity provider is configured. That is the setup a developer is most likely to use for a quick proof of concept, and proofs of concept have a habit of becoming production.
- Prompt templates are code. GitLab’s flaw is in a feature meant to let users customize how prompts are built. Any time users can submit templates, a template engine becomes an execution engine unless it is locked down tightly. According to The Hacker News, it’s the second 9.9 template-injection bug in the same gateway this year, after CVE-2026-1868 in February.
- Agents make outbound calls by design. An orchestrator has to reach out to tool servers, discovery endpoints and APIs. That makes request forgery, the trick of making a server fetch an internal address such as a cloud credential endpoint, a natural fit.
- Shared workspaces blur trust boundaries. SageMaker’s issue lets one teammate act as another. In a collaborative ML project, the contributor role is often given out freely.
The fix for these is not a new kind of AI security product. It’s the same discipline you apply to identity systems and internet-facing apps, applied to a category of software many organizations haven’t put on the list yet.
4. The 59-day gap and the 24-hour clock
One detail deserves attention. Loom version 1.6.1, which closed the 10.0 bug, shipped on 4 August. The CVE and bulletin explaining why it mattered appeared on 2 October, 59 days later. Teams that upgraded promptly were protected all along. Teams that wait for a CVE before acting were running an unauthenticated admin API for two months after a fix existed, and they now have to assume the details are public.
Meanwhile the clock for attackers keeps shrinking. This morning’s look at Microsoft’s 2026 Digital Defense Report covered how flaws are now weaponized in well under a day, and our piece on open-weight models with elite hacking skills explained why AI-assisted exploit writing is no longer limited to a few labs. No exploitation of these flaws has been reported, and CISA’s assessment of the GitLab bug lists exploitation as none. That’s the window to act, not a reason to wait. A flaw scored 10.0 with no login required is exactly the kind that scanners pick up quickly once the bulletin is out.
5. Your if-this-then-that triage list
Rather than a generic checklist, work through these conditions in order. Skip any that don’t apply to you, and finish with the general hardening item at the end, which applies to everyone.
- If you don’t know whether you run any of these → search your cloud accounts, container registries and Git repositories for
loom,ai-gatewayand SageMaker Studio domains today. Ask AI, data and platform teams directly; this kind of tool often lives outside the asset inventory. - If you run Loom for AWS → upgrade to 1.7.0 and patch any code you forked from it. If you can’t patch immediately, take it off any network beyond localhost and configure Amazon Cognito or another identity provider before exposing it again, as AWS recommends.
- If your Loom ran an affected version without an identity provider and was reachable from a network → treat it as compromised. Rotate OAuth client secrets, revoke and reissue access tokens, rotate the credentials of any tools it stored, review the IAM roles attached to its agents and check CloudTrail for unexpected credential use.
- If you self-host GitLab’s AI Gateway → upgrade to 19.2.4, 19.3.2 or 19.4.1 now; there is no workaround. Until you have, consider removing Duo Agent Platform access from users who don’t need it, and afterwards review custom flow configurations and gateway logs for anything unexpected.
- If you use GitLab.com or GitLab Dedicated → no action is needed for this flaw; GitLab has already patched hosted gateways.
- If your teams use SageMaker Unified Studio → restart affected Spaces so they pick up the patched image, move anyone on out-of-support branches (2.8 to 2.13, 3.3 to 3.8) to a supported version, and if Trusted Identity Propagation is enabled, check CloudTrail for one user’s role being used from another member’s Space.
- For every AI gateway or orchestrator you run → put it behind single sign-on, keep its admin API off the internet, give agents and their tools the least privilege that works, and subscribe to the project’s releases, not just its security advisories.
If you’re building a longer-term program, our guide to AI agent security in 2026 covers ownership and least privilege for agents, and the piece on guardrails moving into hardware covers the monitoring tools vendors now offer for agent fleets.
6. The bigger picture: everyone is tightening the agent’s leash
These advisories landed in a week when the industry visibly started reining agents in. On the same day, Apple said it will tighten macOS Full Disk Access because some developers granting AI agents broad access to files, messages and mail could put users at risk, and that the risk will grow as agents get more capable. We covered the consumer side of that permission problem in “Allow Always” is the new “I Agree”. The enterprise side is the control plane: the place where an organization decides which agent can use which tool with which key.
For security leaders, the practical takeaway is to give that layer a name and an owner. Put AI gateways, agent orchestrators, MCP servers and ML workspaces into your asset inventory as their own category. Patch them on the same urgent track as your identity provider and VPN. And when a critical flaw lands in one of them, don’t stop at the upgrade. The value of these systems is the secrets they hold, so a credible fix always includes rotating them.
Frequently asked questions
What is CVE-2026-103956 in Loom for AWS?
It is a missing-authentication flaw in Loom for AWS, an open-source AI agent orchestration platform from AWS Labs, scored CVSS 10.0. In versions before 1.6.1, a deployment with no identity provider configured treated unauthenticated requests as super-admin, letting anyone who could reach it register malicious tool servers, read stored credentials and change agents’ IAM policies. AWS recommends upgrading to 1.7.0 and rotating secrets.
What is the GitLab AI Gateway vulnerability CVE-2026-90970?
It is a CVSS 9.9 template-injection flaw in GitLab’s self-hosted AI Gateway. An authenticated user with Duo Agent Platform access could craft a custom flow configuration that escapes the prompt-template sandbox and runs arbitrary commands on the gateway. It affects versions from 18.1.6 and is fixed in 19.2.4, 19.3.2 and 19.4.1. There is no workaround.
Do I need to do anything if I use GitLab.com?
Not for this flaw. GitLab says GitLab.com, GitLab Dedicated and instances that use GitLab-hosted AI gateways are already patched. Only organizations that run their own self-hosted AI Gateway need to upgrade.
What is the SageMaker Unified Studio flaw CVE-2026-104019?
It is an OS command injection in the startup script of SageMaker Studio Spaces, caused by improper sanitization of connection details. A project contributor could run code in another member’s Space and, with Trusted Identity Propagation enabled, use that member’s temporary credentials. Restarting Spaces picks up the patched image; out-of-support branches get no fix.
Have these AI vulnerabilities been exploited?
As of the 2 October 2026 advisories, no exploitation had been reported for the Loom, GitLab AI Gateway or SageMaker flaws, and no public proof-of-concept was known. Because attackers now weaponize critical flaws quickly, organizations should patch and rotate credentials rather than wait for reports of attacks.
What is an AI control plane and why is it a target?
An AI control plane is the gateway or orchestration layer that routes requests to AI models, registers the tools agents can use, stores the OAuth tokens and API keys they need and assigns cloud permissions. Compromising it gives an attacker every credential and tool behind it at once, which is why it should be secured and patched like an identity provider.
Sources
- The Hacker News: GitLab patches critical 9.9 AI Gateway flaw allowing command execution
- GBHackers: Critical GitLab AI Gateway flaw lets attackers execute arbitrary commands
- Security Affairs: CVE-2026-90970, critical GitLab AI Gateway flaw fixed
- AWS Security Bulletin 2026-124: Loom for AWS
- AWS Security Bulletin 2026-125: SageMaker Distribution command injection
- AWS News Blog: Weekly roundup introducing Loom for AWS (13 July 2026)
- Strix: CVE-2026-103956 record and CVSS vector
- CVE intel: AWS Loom advisory scores for CVE-2026-103956, 103957 and 103958
- Cyber Press: AWS fixes critical Loom and SageMaker flaws
- TechCrunch: Apple tightens macOS Full Disk Access over AI agent risks
