Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands
GitLab patched CVE-2026-90970, a CVSS 9.9 bug letting authenticated users execute commands on self-hosted AI Gateway.
GitLab released emergency fixes for CVE-2026-90970, a CVSS 9.9 improper-neutralization flaw in the Self-Hosted AI Gateway custom flow prompt template feature. An authenticated Duo Agent Platform user can submit a crafted flow configuration that escapes the prompt-template sandbox and runs arbitrary commands on the gateway host. Versions from 18.1.6 are affected and fixed in 19.2.4, 19.3.2, and 19.4.1. GitLab.com, Dedicated, and instances using a GitLab-hosted AI Gateway are already protected.
- CVE-2026-90970 is CVSS 9.9 and allows authenticated command execution.
- Improper neutralization in custom flow prompt templates escapes the sandbox.
- Affects self-hosted AI Gateway from 18.1.6 through unpatched 19.2, 19.3, and 19.4.
- Fixed in 19.2.4, 19.3.2, and 19.4.1; GitLab-hosted gateways already patched.
- Requires low-privileged Duo Agent Platform access and no user interaction.
Vulnerabilities mentionedAll →
- CVE-2026-909709.9<1%Prompt sandbox escape to RCE in GitLab AI Gatewaypublished · GitLab AI Gateway PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-90970 | Prompt sandbox escape to RCE in GitLab AI Gateway |
Full article530 words · extracted from gbhackers.com · click to collapse
GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute arbitrary commands on vulnerable AI Gateway deployments.
The flaw, tracked as CVE-2026-90970, carries a CVSS severity score of 9.9 out of 10. The company released GitLab AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue.
The vulnerability affects the AI Gateway component used to support GitLab Duo Self-Hosted capabilities, including AI-assisted development workflows deployed within customer-controlled environments.
Critical GitLab AI Gateway Flaw
GitLab said it has already reached out to potentially affected Self-Hosted AI Gateway customers before publicly publishing the security advisory. CVE-2026-90970 is described as an improper neutralization vulnerability in GitLab AI Gateway’s custom flow prompt template functionality.
Under certain conditions, an authenticated user with access to the Duo Agent Platform could create or submit a specially crafted flow configuration that escapes the intended prompt-template sandbox. Successful exploitation could lead to arbitrary command execution on the AI Gateway host or environment.
This creates a significant risk because command execution could enable an attacker to access sensitive development data, manipulate AI workflow configurations, steal service credentials, move laterally within connected infrastructure, or disrupt AI-enabled development operations.
The CVSS 3.1 vector for the issue is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The score reflects that exploitation can occur remotely with low attack complexity and does not require user interaction, although the attacker must first have low-privileged authenticated access to the affected Duo Agent Platform functionality.
Affected GitLab AI Gateway Versions
The issue impacts GitLab AI Gateway installations beginning with version 18.1.6 and affects the following version ranges:
| Affected release line | Vulnerable versions | Fixed version |
|---|---|---|
| GitLab AI Gateway 18.x through 19.2 | 18.1.6 through versions before 19.2.4 | 19.2.4 |
| GitLab AI Gateway 19.3 | 19.3 through versions before 19.3.2 | 19.3.2 |
| GitLab AI Gateway 19.4 | 19.4 through versions before 19.4.1 | 19.4.1 |
GitLab-hosted AI Gateway customers are not affected by this remediation requirement. The company confirmed that it has already deployed a fix for GitLab-hosted AI Gateway environments.
As a result, customers using GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances configured to use a GitLab-hosted AI Gateway are protected and do not need to take action.
Mitigation
Organizations running Self-Hosted AI Gateway should prioritize upgrading to version 19.2.4, 19.3.2, or 19.4.1 based on their supported release track.
Security teams should also review Duo Agent Platform access assignments, inspect custom flow configurations for unexpected or unauthorized changes, and monitor AI Gateway logs for suspicious command execution activity.
Because exploitation requires authenticated access, restricting Duo Agent Platform permissions and reviewing accounts with access to custom flow capabilities can reduce exposure while patching is underway. However, access controls should not replace installing the security update.
GitLab’s fix addresses a growing security concern around AI workflow platforms: prompt and template components must be strictly isolated from underlying execution environments.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.