GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways.
GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.
GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.
The issue affects the way the AI Gateway handles custom flow prompt templates. According to GitLab, a user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt template sandbox and execute commands on the AI Gateway host.
“GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.” reads the advisory.
The important point is that the attack does not require an unauthenticated connection. GitLab’s advisory does not provide further details about the exact conditions required to exploit the flaw or the permissions needed beyond that access.
GitLab credited the HackerOne researcher invisiblemeerkat with responsibly reporting the vulnerability.
The GitLab AI Gateway is basically the middle layer between GitLab Duo and the AI models. GitLab Duo provides AI features such as code suggestions, chat, code explanation and agentic workflows. The AI Gateway receives the requests from GitLab, prepares the prompts and communicates with the underlying LLMs.
GitLab operates its own cloud-based gateway, but organizations can also deploy an AI Gateway inside their own infrastructure.
GitLab says the security fix has already been deployed to its own hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance connected to a GitLab-hosted gateway therefore do not need to take action.
The customers that need to patch are those running a GitLab Self-Hosted AI Gateway. GitLab has already contacted those customers directly and strongly recommends updating affected installations immediately.
Self-hosting the gateway is designed for organizations that want to keep AI requests and responses inside their own environment. In a fully self-hosted configuration, GitLab, the AI Gateway and the selected AI models can all operate within the organization’s infrastructure.
Below are the affected AI Gateway releases:
| Affected version | Fixed version |
|---|---|
| 18.1.6 through 19.2.3 | 19.2.4 |
| 19.3.0 through 19.3.1 | 19.3.2 |
| 19.4.0 | 19.4.1 |
The AI Gateway sits between GitLab’s AI features and the underlying models. In a self-hosted deployment, it processes requests between the GitLab instance and the organization’s AI infrastructure.
The service also has access to sensitive authentication material. GitLab’s installation documentation says that self-hosted deployments require signing and validation keys for JSON Web Tokens. These keys are passed to the gateway as environment variables.
For that reason, command execution on the gateway could provide an attacker with a foothold inside infrastructure that handles AI requests and authentication. The exact impacts would depend on how the gateway is deployed and what access it has to the rest of the organization’s environment.
GitLab’s October 2 advisory does not say that CVE-2026-90970 has been exploited in the wild. It also does not publish a proof of concept or technical exploitation steps.
That leaves several important questions unanswered, including the precise flow configuration needed to escape the template sandbox and the exact conditions under which the resulting command execution can be reached.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Source: SecurityAffairs
Source Link: https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html