GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab patched CVE-2026-90970, a CVSS 9.9 command-execution flaw in self-hosted AI Gateway.
GitLab fixed CVE-2026-90970, a CVSS 9.9 flaw in its self-hosted AI Gateway that lets a logged-in Duo Agent Platform user escape a custom-flow prompt-template sandbox and run commands on the gateway. Fixes are in gateway versions 19.2.4, 19.3.2, and 19.4.1. GitLab.com, GitLab Dedicated, and customers using a GitLab-hosted gateway do not need to act. CISA's CVE assessment lists exploitation as none, and the bug is the same CWE-1336 template-engine class as February's CVE-2026-1868.
- CVE-2026-90970 scores CVSS 9.9 and allows gateway command execution.
- Only organizations hosting their own AI Gateway must patch.
- Fixed versions are 19.2.4, 19.3.2, and 19.4.1.
- CISA records exploitation as none and lists no public PoC.
- Issue is CWE-1336, same class as February CVE-2026-1868.
Vulnerabilities mentionedAll →
- CVE-2026-18689.9<1%GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6…published
- CVE-2026-909709.9—Prompt sandbox escape to RCE in GitLab AI Gatewaypublished · GitLab AI Gateway
Full article661 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalOct 02, 2026Vulnerability / Application Security
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.
The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The flaw is tracked as CVE-2026-90970. GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
GitLab runs AI Gateways for its customers and has already fixed them. Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said.
Self-managed customers can instead host their own gateway, an option GitLab offers for keeping AI request and response data inside the customer's own environment. GitLab strongly recommends that those customers update immediately. It sent that guidance to customers with self-hosted gateways before it published the advisory.
The advisory does not say whether the flaw has been used in attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an assessment to the CVE record on October 2 that lists exploitation as "none." CISA's other two values cover a public proof of concept and active exploitation.
Affected and Fixed Versions
The versions below are AI Gateway versions. The gateway is installed as its own Docker image or Helm chart and has its own update steps.
| Gateway version in use | First fixed version |
|---|---|
| 18.1.6 or later, before 19.2.4 | 19.2.4 |
| 19.3, before 19.3.2 | 19.3.2 |
| 19.4, before 19.4.1 | 19.4.1 |
To update a Docker deployment, stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee. Helm deployments set the new tag in the chart's image setting.
No fixed version is listed below 19.2.4. That leaves every gateway release from 18.1.6 through the 19.1 line inside the affected range.
GitLab's install guide tells administrators to use the gateway image that matches their GitLab minor version. The advisory does not say whether a 19.2.4 gateway works with GitLab 19.1 or earlier, or whether fixes for the older lines are planned.
As of October 2, GitLab's maintenance policy listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes. Those are the same three lines that got the gateway fix.
No workaround is listed for gateways that cannot be updated yet. The advisory also gives no way to check whether a gateway was attacked before it was updated.
What Is Known About the Flaw
The flaw is in the prompt template of a custom flow, according to the advisory's title. A custom flow is an AI-powered workflow that users create on the Duo Agent Platform to automate multi-step tasks.
A logged-in user with Duo Agent Platform access could have used the flaw to "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said. The escape could lead to arbitrary command execution on the gateway.
The conditions the attack needs are not described, and no user role is named beyond Duo Agent Platform access.
A self-hosted gateway holds signing keys for JSON Web Tokens (JWT), which GitLab's install guide says must be treated as sensitive credentials. It also connects to the GitLab instance and to the organization's AI model providers.
GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw.
In February, GitLab fixed another gateway flaw, CVE-2026-1868, which it also rated 9.9. A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway.
Both flaws are template engine weaknesses of the same class, CWE-1336. The new advisory does not mention the February flaw.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.