GitLab patches critical AI Gateway flaw allowing remote code execution
GitLab released urgent fixes for CVE-2026-90970, a critical vulnerability in self-hosted AI Gateways that allows command execution via crafted prompt templates.
Este artículo está disponible solo en inglés.
GitLab has issued an emergency patch for a critical security vulnerability in its AI Gateway software, rated 9.9 on the CVSS scale. The flaw, tracked as CVE-2026-90970, allows authenticated users with specific platform access to execute arbitrary commands on self-hosted gateway instances. The company disclosed the issue on October 2, 2026, urging immediate updates for affected deployments.
What happened
The vulnerability resides in the AI Gateway, a component that connects GitLab instances to external AI models. While GitLab manages and secures this service for customers on GitLab.com and GitLab Dedicated, organizations that choose to self-host their own gateway are responsible for applying the fix. This self-hosted option is typically used by enterprises that need to keep AI request and response data within their own infrastructure for compliance or privacy reasons.
GitLab rated the severity as critical due to the potential impact. A successful exploit could allow an attacker to run commands directly on the server hosting the gateway. The company stated that it had already secured its own hosted instances before public disclosure. However, self-managed customers were advised to update immediately upon receiving private guidance prior to the public advisory. There is no indication that the flaw has been exploited in the wild; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed exploitation status as "none" in its assessment added on October 2.
How it works
The root cause of the vulnerability lies in the prompt template handling within custom flows on the Duo Agent Platform. Custom flows are AI-powered workflows that users create to automate multi-step tasks. According to GitLab, a logged-in user with access to the Duo Agent Platform could craft a specific flow configuration that escapes the prompt template sandbox. This escape mechanism bypasses security boundaries intended to isolate user inputs from system-level operations.
Once the sandbox is escaped, the attacker can achieve arbitrary command execution on the gateway server. This is particularly dangerous because self-hosted gateways store sensitive credentials, including signing keys for JSON Web Tokens (JWT). These keys must be treated as high-value secrets, as they authenticate communications between the GitLab instance and the gateway. Additionally, the gateway maintains connections to both the internal GitLab instance and external AI model providers, potentially offering a pivot point for further lateral movement if compromised. The vulnerability class is identified as CWE-1336, which relates to improper neutralization of special elements used in a template engine.
Key details
- CVE Identifier: CVE-2026-90970 with a CVSS score of 9.9 out of 10.
- Affected Component: Self-hosted GitLab AI Gateway installations.
- Prerequisites: Attacker must be a logged-in user with Duo Agent Platform access.
- Fixed Versions: Gateway versions 19.2.4, 19.3.2, and 19.4.1.
- Unsupported Versions: No fixes are provided for gateway versions earlier than 19.2.4, leaving versions 18.1.6 through 19.1 vulnerable.
- Reporter: The flaw was reported by HackerOne user invisiblemeerkat.
Why it matters
For engineering teams running self-hosted GitLab instances, this vulnerability represents a significant risk to infrastructure integrity. The ability to execute arbitrary commands on a server that holds JWT signing keys and connects to core development tools is a severe threat vector. Unlike many vulnerabilities that require complex chaining or privileged admin access, this flaw can be triggered by any user with Duo Agent Platform permissions, which may include a broader set of developers than just system administrators.
The recurrence of similar flaws highlights a persistent challenge in integrating generative AI into secure development environments. In February 2026, GitLab patched another critical gateway flaw, CVE-2026-1868, which also allowed code execution via crafted flow definitions and shared the same CWE-1336 classification. This pattern suggests that template injection remains a difficult problem to solve in AI workflow engines. Teams must recognize that adding AI capabilities introduces new attack surfaces that require rigorous sandboxing and input validation, distinct from traditional application security measures.
What you can do
- Check your current AI Gateway version immediately to determine if you are running a vulnerable release between 18.1.6 and 19.4.0.
- Update your Docker container or Helm chart to one of the fixed versions: 19.2.4, 19.3.2, or 19.4.1.
- Rotate JWT signing keys stored on the gateway if you suspect any unauthorized access prior to patching.
- Review user access lists for the Duo Agent Platform and restrict permissions to only those who strictly require it.
- Monitor gateway logs for unusual process executions or unexpected outbound connections to AI providers.
- Plan for migration if you are on a gateway version older than 19.2.4, as no patch is available for those lines.


