Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
GitLab patched CVE-2026-90970, a CVSS 9.9 flaw letting authenticated Duo users execute commands on self-hosted AI Gateways.
GitLab patched CVE-2026-90970, a CVSS 9.9 flaw in self-hosted AI Gateway deployments used for GitLab Duo. An authenticated user with Duo Agent Platform access can submit a crafted flow configuration that escapes the prompt-template sandbox and executes arbitrary commands on the gateway. Affected builds start at 18.1.6 and run through releases before 19.2.4, 19.3.2, and 19.4.1. GitLab-hosted gateways are already fixed, and the advisory reports neither a public exploit nor active exploitation.
- CVE-2026-90970 scores CVSS 9.9 and needs Duo Agent Platform access.
- Crafted flow templates escape the prompt sandbox and run gateway commands.
- Fixed releases are AI Gateway 19.2.4, 19.3.2, and 19.4.1.
- GitLab-hosted gateways are patched; only self-hosted gateways need upgrades.
- No public exploit payload or active exploitation was reported.
Vulnerabilities mentionedAll →
- CVE-2026-909709.9—Prompt sandbox escape to RCE in GitLab AI Gatewaypublished · GitLab AI Gateway
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-90970 | Prompt sandbox escape to RCE in GitLab AI Gateway GitLab AI Gateway contains a prompt-template sandbox escape tracked as CVE-2026-90970 (CWE-1336). An authenticated user who already has Duo Agent Platform access can, under certain conditions, submit a specially crafted flow configuration that breaks out of the prompt template sandbox. The result is arbitrary command execution on the AI Gateway, scored CVSS 3.1 9.9 (network, low complexity, low privileges, changed scope, and high impact on confidentiality, integrity, and availability). Affected builds are AI Gateway 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. No public proof of concept is known and the issue is not in CISA KEV. Do: Upgrade GitLab AI Gateway to 19.2.4, 19.3.2, or 19.4.1 on the matching release line. Until then, restrict Duo Agent Platform access to trusted users and review flow configurations and AI Gateway hosts for unexpected process or command activity. |
Full article597 words · extracted from cybersecuritynews.com · click to collapse
GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features.
The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early guidance on the required updates.
GitLab AI Gateway Vulnerability
The vulnerability involves improper handling of custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could submit a specially crafted flow configuration that escapes the prompt template sandbox. Successful exploitation could then allow arbitrary commands to run on the AI Gateway.
A sandbox is meant to keep template processing within a controlled boundary. In this case, GitLab says crafted input could cross that boundary and reach command execution. The disclosed impact is therefore more serious than changing an AI response: it could affect the service that processes AI requests.
The published CVSS vector describes a network-accessible attack with low complexity, low privileges, and no required user interaction. It assigns high impact to confidentiality, integrity, and availability. However, this is not an unauthenticated flaw; the attacker needs a valid account with Duo Agent Platform access.
GitLab credited security researcher invisiblemeerkat with responsibly reporting the issue. The advisory does not provide an exploit payload, identify the template engine involved, or report active exploitation. Those limits matter: the release confirms a critical security weakness, but it does not establish that attackers have already used it.
Affected AI Gateway releases include versions starting at 18.1.6 and earlier than 19.2.4, the 19.3 branch before 19.3.2, and the 19.4 branch before 19.4.1. These version ranges apply to the AI Gateway component. Administrators should check the gateway deployment rather than rely only on their main GitLab instance version.
GitLab has already deployed the fix to its hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-hosted AI Gateway are protected and need no action for this issue. Customers operating their own affected AI Gateway must install the update themselves.
The distinction matters because GitLab’s self-hosted AI setup lets organizations manage requests to their chosen model backends within their own environment. Cybersecurity News previously covered a separate GitLab Duo prompt injection vulnerability involving source code exposure. That earlier issue should not be confused with this gateway sandbox escape.
Administrators should follow GitLab’s AI Gateway installation and upgrade documentation to deploy a patched image. For Docker installations, GitLab instructs users to stop and remove the existing container, then pull and run the new image with the correct environment variables. Verify the deployed image digest and run the available health checks afterward.
For Kubernetes and Helm deployments, GitLab warns that cached images can prevent updated code from being pulled. Its guidance recommends image digests or an appropriate pull policy. Administrators should also restrict unnecessary outbound gateway traffic while preserving required connections. These controls support hardening, but the immediate priority remains installing a fixed AI Gateway release without delay.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.