---
title: GitLab ประกาศแก้ไขช่องโหว่ร้ายแรงใน「GitLab AI Gateway」
url: https://www.dataloco.com/th/gitlab-gitlab-ai-gateway
published: 2026-10-07T10:01:49+00:00
language: th
section: ความปลอดภัย
source: https://www.security-next.com/191010
organizations: gitlab
publisher: Dataloco
---

# GitLab ประกาศแก้ไขช่องโหว่ร้ายแรงใน「GitLab AI Gateway」

GitLab ได้เปิดเผยถึงช่องโหว่ร้ายแรงใน「GitLab AI Gateway」ซึ่งอาจทำให้มีความเสี่ยงในการเรียกใช้คำสั่งที่ไม่พึงประสงค์ โดยได้ปล่อยเวอร์ชันแก้ไขใหม่ และเรียกร้องให้ผู้ใช้ที่มีสภาพแวดล้อมเซลฟ์โฮสต์ทำการอัปเดตโดยด่วน

ช่องโหว่นี้ถูกระบุว่าเป็น「CVE-2026-90970」ซึ่งมีการประมวลผลเทมเพลตโปรมต์ของฟลว์ที่กำหนดเอง โดยผู้ใช้ที่ได้รับการรับรองสามารถหลีกเลี่ยง sandbox และเรียกใช้คำสั่งที่ไม่พึงประสงค์ได้ภายใต้เงื่อนไขบางประการ

คะแนนพื้นฐานจากระบบการประเมินช่องโหว่ทั่วไป「CVSSv3.1」อยู่ที่「9.9」ซึ่งจัดอยู่ในระดับ「Critical」

GitLab ได้ปล่อยเวอร์ชันแก้ไข「GitLab AI Gateway 19.4.1」「19.3.2」「19.2.4」และแนะนำให้ผู้ใช้ทำการอัปเดต ขณะที่「AI Gateway」ที่บริษัทโฮสต์ได้มีการแก้ไขเรียบร้อยแล้ว

## This story in other languages

- [Indonesia](https://www.dataloco.com/id/vulnerabilitas-serius-ditemukan-pada-gitlab-ai-gateway)
- [Deutsch](https://www.dataloco.com/de/gitlab-veroffentlicht-sicherheitsupdate-fur-gitlab-ai-gateway)
- [Español](https://www.dataloco.com/es/gitlab-lanza-una-actualizacion-para-abordar-una-grave-vulnerabilidad-en-gitlab-ai-gateway)
- [Français](https://www.dataloco.com/fr/vulnerabilite-critique-dans-le-gitlab-ai-gateway)
- [Nederlands](https://www.dataloco.com/nl/gitlab-ai-gateway-heeft-ernstige-kwetsbaarheid-ontdekt)
- [Norsk](https://www.dataloco.com/no/gitlab-ai-gateway-har-kritisk-sarbarhet-som-kan-tillate-kommandoeksekvering)
- [Polski](https://www.dataloco.com/pl/wykryto-powazna-luke-w-gitlab-ai-gateway)
- [العربية](https://www.dataloco.com/ar/kshf-thghr-khtyr-fy-gitlab-ai-gateway)
