GitLab AI Gateway CVE-2026-90970: 9.9 Flaw Allows Command Execution
A prompt-template sandbox escape in the GitLab AI Gateway lets an authenticated Duo Agent Platform user run commands on the gateway host. Only self-hosted gateways need action, and no workaround is listed.
Key Takeaways
- CVE-2026-90970 (CVSS 9.9) lets a logged-in user with Duo Agent Platform access escape the prompt-template sandbox of a custom flow and execute commands on the AI Gateway.
- Only organisations that self-host the gateway are affected. GitLab says GitLab.com and GitLab Dedicated are not affected and have already been patched.
- Fixed gateway versions are 19.2.4, 19.3.2 and 19.4.1. The advisory lists no workarounds, so upgrading is the only remediation.
- It is the second critical template-handling flaw in this component this year, which suggests user-authored flow definitions should be treated as untrusted code.
What was disclosed
On 2 October 2026 GitLab published an advisory for a critical flaw in the AI Gateway, the service that connects a GitLab instance to AI models. The Hacker News reports that it is tracked as CVE-2026-90970 with a CVSS score of 9.9.
The root cause is a weakness in the prompt template used by custom flows on the Duo Agent Platform, classified as CWE-1336 (improper neutralisation of special elements in a template engine). A logged-in user with Duo Agent Platform access could escape the template sandbox through a specially crafted flow configuration and run arbitrary commands on the gateway.
Who needs to act
Only self-managed customers running their own gateway are exposed. GitLab.com and GitLab Dedicated are reported as not affected, and GitLab has already patched its hosted instances.
- Affected: gateway 18.1.6 or later and before 19.2.4; 19.3 before 19.3.2; 19.4 before 19.4.1.
- Fixed: 19.2.4, 19.3.2 and 19.4.1.
- Mitigations: none listed in the advisory.
- Exploitation: CISA's assessment shows no known exploitation as of the disclosure date.
The report credits the HackerOne researcher "invisiblemeerkat" with the finding.
Why it matters beyond GitLab
The precondition is an authenticated account, which lowers the bar less than it sounds. On a large self-hosted instance, Duo Agent Platform access may be granted to many developers. Any compromised developer account, such as one taken over through a phished token or a malicious dependency, becomes a path to code execution on a host that sits between the source-control platform and the model backends.
That placement is the real exposure. An AI gateway typically holds the credentials and network reach needed to call model providers, and it processes prompts and repository context. We cannot say from the advisory what a particular deployment exposes, so teams should work that out for their own environment: which secrets live on the gateway host, what it can reach on the network, and who can author flows.
A repeat pattern
The Hacker News notes that a similar CWE-1336 weakness was patched in February 2026 as CVE-2026-1868, also rated 9.9. GitLab's earlier patch notes describe that issue as insecure template expansion of user-supplied data in crafted flow definitions, fixed in gateway 18.6.2, 18.7.1 and 18.8.1. Two critical findings in the same class suggest that template sandboxing is a hard control to get right when the template author is an end user.
Practical steps
- 1Inventory self-hosted AI Gateways and confirm their versions, since gateway versions are tracked separately from the GitLab instance.
- 2Upgrade to 19.2.4, 19.3.2 or 19.4.1, depending on your release line.
- 3Restrict who has Duo Agent Platform access and who can create or edit custom flows until the patch is applied.
- 4Run the gateway with least privilege: minimal secrets, egress filtering, and no network path to internal systems it does not need.
- 5Review gateway host logs and flow definitions for unexpected commands or unfamiliar flow changes.
Frequently Asked Questions
Is GitLab.com affected by CVE-2026-90970?
No. GitLab says GitLab.com and GitLab Dedicated are not affected and its hosted instances are already patched. Only organisations that run their own AI Gateway must upgrade.
Which gateway versions fix the flaw?
Versions 19.2.4, 19.3.2 and 19.4.1. Affected releases are 18.1.6 and later before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.
Is there a workaround if I cannot patch immediately?
The advisory lists none. Interim risk reduction, such as limiting Duo Agent Platform access and flow authoring, reduces who can reach the flaw but does not remove it.