GitLab has patched a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970, that lets an authenticated attacker escape the prompt template sandbox and run arbitrary commands on self-hosted gateway servers. Rated 9.9 out of 10 on the CVSS scale, it affects only organizations that run their own AI Gateway infrastructure. If your team hosts GitLab’s AI Gateway on your own servers, patch to 19.2.4, 19.3.2, or 19.4.1 immediately.
What CVE-2026-90970 Is
CVE-2026-90970 is an improper neutralization flaw in the custom flow prompt templates used by GitLab’s AI Gateway, the service that powers GitLab Duo’s AI-assisted development features. Under certain conditions, an authenticated user with access to the Duo Agent Platform could submit a specially crafted flow configuration and break out of the prompt template sandbox.
That sandbox escape leads to arbitrary command execution on the underlying AI Gateway host or container. Because the gateway sits between GitLab and the AI models behind Duo, a takeover could expose prompts, source code snippets sent for AI analysis, model credentials, and other secrets passing through the gateway. GitLab rates the issue critical with a CVSS 3.1 vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: reachable over the network, low attack complexity, only basic privileges required, no user interaction needed, and impact that extends beyond the gateway itself.
Which Versions Are Affected
The flaw affects GitLab AI Gateway releases from version 18.1.6 up to, but not including, 19.2.4. It also affects releases in the 19.3 branch before 19.3.2 and releases in the 19.4 branch before 19.4.1.
The fixed versions are 19.2.4, 19.3.2, and 19.4.1, depending on which release branch you run. GitLab released the patches on October 2, 2026, and said it had already contacted self-hosted gateway customers with the guidance before the public disclosure.
Who Needs to Take Action
Only organizations that operate their own self-hosted AI Gateway need to act. GitLab.com customers, GitLab Dedicated customers, and any self-managed instances that point at a GitLab-hosted gateway are already protected, because GitLab deployed the fix across its hosted gateway environment before disclosing the issue.
A common mistake to avoid
The AI Gateway is a separate component from the core GitLab application. Upgrading the main GitLab Community Edition or Enterprise Edition instance alone does not fix the problem. Administrators should check the deployed AI Gateway image or Helm configuration specifically, not assume the standard GitLab upgrade took care of it.
This matters because GitLab Duo adoption keeps growing inside engineering teams, and a surprising number of admins treat the gateway as part of the main GitLab install. It is not.
What to Do Right Now
If you run a self-hosted GitLab AI Gateway, treat this as urgent, especially in environments where developers have been granted Duo Agent Platform access and can build custom flow configurations.
- Upgrade the AI Gateway to 19.2.4, 19.3.2, or 19.4.1, matching your supported release branch.
- After patching, review gateway logs for unusual flow configurations or unexpected command activity that could indicate someone was testing the sandbox.
- Rotate AI provider API keys and any secrets stored in the gateway environment, since a successful attacker could have read them.
- Review which users have Duo Agent Platform access and custom flow permissions, and trim anything that is not needed.
Is It Being Exploited?
As of October 3, 2026, GitLab has not confirmed exploitation of CVE-2026-90970 in the wild, and the flaw has not been added to CISA’s Known Exploited Vulnerabilities catalog. That said, the same disclosure cycle included a separate critical GitLab flaw that is actively exploited: a path traversal vulnerability in GitLab Community Edition and Enterprise Edition, CVE-2026-85706, rated a perfect 10.0, which CISA recently added to its KEV catalog. If you have not applied GitLab’s latest security release for the core platform either, now is the time.
This is the second critical sandbox flaw in the AI Gateway component in recent memory. In February 2026, GitLab patched CVE-2026-1868, another 9.9-rated issue in the same component, also exploitable through a crafted flow definition. Both flaws trace back to insufficient sanitization in the template engine behind Duo Agent Platform flow configurations. The pattern is clear: wherever AI agents and prompt templates touch infrastructure, attackers will probe the seams.
Why This One Stands Out
This vulnerability lands at an uncomfortable intersection. It is an AI feature, not a traditional server component, yet exploiting it gives attackers a shell on real infrastructure with real credentials. Teams that rolled out GitLab Duo quickly for productivity gains may not have applied the same patching discipline to the gateway that they apply to their GitLab servers. This disclosure is a reminder that every AI component in your stack is infrastructure now, and it deserves infrastructure-grade maintenance.
Security teams watching this space will want to keep an eye on how GitLab hardens the Duo Agent Platform’s custom flows going forward. Two sandbox escapes in one year suggests the component needs a deeper fix than point patches.
We have been tracking critical infrastructure flaws closely this year, including the F5 BIG-IP zero-day, the Cisco SD-WAN zero-day, and the FortiMail zero-day, each of which followed the same playbook: check what you run, patch the specific component, and rotate exposed secrets.
FAQ
What is CVE-2026-90970?
CVE-2026-90970 is a critical vulnerability in GitLab’s self-hosted AI Gateway. It lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox through a crafted flow configuration and execute arbitrary commands on the gateway server. It scores 9.9 on the CVSS scale.
Which GitLab versions fix CVE-2026-90970?
GitLab fixed the flaw in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1. If you run the 19.2 branch, update to 19.2.4; the 19.3 branch, update to 19.3.2; the 19.4 branch, update to 19.4.1.
Do I need to patch if I use GitLab.com?
No. GitLab.com, GitLab Dedicated, and any instances using a GitLab-hosted AI Gateway were already patched before the disclosure. Only self-hosted AI Gateway deployments require action.
Is CVE-2026-90970 being exploited in the wild?
As of October 3, 2026, no exploitation in the wild has been confirmed and the flaw is not in CISA’s KEV catalog. However, a separate GitLab flaw disclosed around the same time, CVE-2026-85706, is actively exploited and on the KEV list, so patching both is wise.
Does upgrading GitLab CE or EE fix the AI Gateway flaw?
No. The AI Gateway is a separate component from the core GitLab application. You must upgrade the gateway deployment itself, checking the AI Gateway image or Helm configuration, rather than assuming a main GitLab upgrade covers it.
