Skip to content

GitLab patches 9.9 RCE in self-hosted AI Gateway (CVE-2026-90970)

CVE-2026-90970, a CVSS 9.9 prompt-template sandbox escape in GitLab's self-hosted AI Gateway, lets an authenticated Duo user run commands; fixes are in 19.2.4, 19.3.2, and 19.4.1.

Published 3 min read

GitLab has patched CVE-2026-90970, a CVSS 9.9 flaw in the self-hosted AI Gateway that lets an authenticated user with Duo Agent Platform access break out of a prompt-template sandbox and run arbitrary commands on the gateway host. The fix shipped in the AI Gateway 19.4.1 patch release. Only self-hosted deployments are affected; GitLab.com is not.

What the bug does

Per GitLab's advisory, the flaw lives in the prompt template of a custom flow. An authenticated user holding Duo Agent Platform access can "escape the prompt template sandbox via a specially crafted flow configuration," leading to arbitrary command execution on the self-hosted gateway. GitLab classes it as a template-engine weakness (CWE-1336, improper neutralization of special elements used in a template engine) — a server-side template injection in the layer that renders AI flow prompts, not a model-level prompt injection.

The precondition is a valid account with platform access, not full admin, so the barrier is low in any org that has rolled Duo out broadly.

Affected versions

GitLab lists the self-hosted AI Gateway as affected across:

  • 18.1.6 through 19.1.x
  • 19.3 before 19.3.2
  • 19.4 before 19.4.1

Fixes are in 19.2.4, 19.3.2, and 19.4.1.

Exploitation status

No in-the-wild exploitation has been reported. CISA's Vulnrichment assessed exploitation as "none" as of October 2; there is no public PoC at the time of writing. GitLab says it reached affected self-hosted customers directly before the public disclosure. The flaw was reported through GitLab's HackerOne program by a researcher using the handle invisiblemeerkat.

Action checklist

  1. Upgrade the AI Gateway to 19.4.1, 19.3.2, or 19.2.4, matching your branch. The gateway is a separate component from the GitLab application server — patch it on its own track.
  2. Inventory who has Duo Agent Platform access. The exploit needs an authenticated user with that access; treat it as a privileged role and prune accounts that do not need it.
  3. If you cannot patch immediately, restrict network access to the self-hosted gateway and review custom flow configurations for anything you did not author.
  4. Check gateway host logs for unexpected process execution or flow-configuration changes since the gateway went live.

Context

This is the second 9.9-rated hole in GitLab's AI Gateway this year — GitLab flags it as the same class as a prompt-template weakness patched in February 2026. The pattern is the real story: the gateway that fronts AI features is a new, internet-reachable component that executes attacker-influenced template input, and it is being hardened in production rather than before shipping. Anyone running self-hosted Duo should treat the AI Gateway as a first-class attack surface on par with the Rails app, with its own patch cadence and its own access review.

Related stories