GitLab patches critical CVSS 9.9 command execution flaw in self-hosted AI Gateway

GitLab has fixed CVE-2026-90970, a critical flaw in its self-hosted AI Gateway that lets authenticated Duo Agent Platform users escape a prompt template sandbox and run commands.

GitLab patches critical CVSS 9.9 command execution flaw in self-hosted AI Gateway

At a glance

  • CVE-2026-90970 carries a CVSS score of 9.9 and affects self-hosted GitLab AI Gateway deployments.
  • Authenticated users with Duo Agent Platform access can escape the prompt template sandbox via a crafted flow configuration.
  • Fixed versions are 19.2.4, 19.3.2 and 19.4.1; GitLab.com and GitLab Dedicated need no action.
  • No in-the-wild exploitation has been reported, and no workaround is available.

GitLab has released security updates for its self-hosted AI Gateway to fix a critical vulnerability that could allow an authenticated user to execute arbitrary commands on the gateway service, according to BleepingComputer and The Hacker News. The flaw, tracked as CVE-2026-90970, has a CVSS score of 9.9, and GitLab is urging all Self-Managed customers running the component to upgrade immediately.

What happened

GitLab disclosed the issue on October 2 alongside new releases of the AI Gateway. "These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately," the company said, as quoted by BleepingComputer.

According to BleepingComputer, GitLab carried out targeted outreach to self-hosted customers before publishing the advisory. The Hacker News reports that the vulnerability was reported through GitLab's HackerOne bug bounty program by a researcher using the handle invisiblemeerkat.

Technical details

The bug stems from improper neutralization of user input in the prompt template used by custom flows on the GitLab Duo Agent Platform. According to both outlets, a logged-in user with access to the platform could escape the prompt template sandbox through a specially crafted flow configuration and potentially achieve arbitrary command execution on the AI Gateway.

The Hacker News notes that this is not the first template engine weakness of this kind to hit the product: in February 2026, GitLab patched CVE-2026-1868, another CVSS 9.9 flaw classified as a template injection issue (CWE-1336) that also enabled code execution.

No active exploitation has been reported. The Hacker News adds that CISA's assessment rated exploitation as "none" at the time of disclosure.

Who is affected

Per The Hacker News, the following AI Gateway versions are vulnerable:

  • 18.1.6 through 19.2.3
  • 19.3.0 through 19.3.1
  • 19.4.0

Only organizations hosting the AI Gateway themselves are at risk. GitLab.com and GitLab Dedicated customers, as well as customers using the GitLab-hosted gateway, are already protected and do not need to take any action, according to the reports.

What to do

Administrators of self-hosted AI Gateway installations should upgrade to 19.2.4, 19.3.2 or 19.4.1, including updating any Docker images used to run the gateway, as soon as possible. The Hacker News reports that no workaround exists for systems that cannot be updated right away.

Until the patch is applied, organizations may want to review which users have access to the Duo Agent Platform and audit recently created or modified custom flow configurations for unexpected changes. Because the gateway often sits close to source code and CI/CD infrastructure, a compromise of the service could have wider consequences for the development environment.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.