// 2 CRITICAL · 6 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H→
CVE-2026-90970, rated CVSS 9.9, allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands on self-hosted AI Gateway instances. Cloud instances are already protected.

GitLab released critical patches for its AI Gateway on October 2, 2026. The service mediates requests between self-hosted instances and AI models. The vulnerability, tracked as CVE-2026-90970 with a CVSS score of 9.9, allows authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the server through a prompt template sandbox escape. The stakes are significant: while GitLab's cloud instances are already protected, customers running the AI Gateway on their own infrastructure must update immediately.

Key Takeaways
  • CVE-2026-90970 is rated critical with CVSS 9.9 per the NVD record: complete impact on confidentiality, integrity, and availability.
  • The attack requires authentication and Duo Agent Platform access, but no additional user interaction (UI:N) and has changed scope (S:C), indicating potential propagation.
  • The mechanism is improper neutralization (CWE-1336): a malformed flow configuration escapes the template sandbox.
  • Only self-hosted deployments are vulnerable: GitLab.com and GitLab Dedicated are already protected with no customer action required.

The Mechanism: How the Template Engine Becomes an Execution Vector

The flaw resides in the GitLab AI Gateway's prompt template engine. According to the official advisory, an authenticated user with Duo Agent Platform access can construct a "specially crafted flow configuration" that escapes the prompt template sandbox. The escape enables arbitrary command execution directly on the AI Gateway server.

The CWE-1336 classification (improper neutralization) indicates the system fails to adequately sanitize input that can alter template parsing logic. In AI services, where prompt templates are dynamically structured to orchestrate calls to language models, this attack surface is particularly insidious: seemingly "semantic" input (a flow configuration) becomes a vehicle for code execution.

The CVSS vector confirms the severity: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Network access, low complexity, low privileges, no user interaction required, changed scope. The last parameter is critical: it suggests impact can extend beyond the compromised component, typical of scenarios where the AI Gateway — positioned between the GitLab instance and model providers — acts as a transit point with visibility into traffic and potentially service credentials.

"GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway" — Official GitLab Advisory

Affected Versions and Patches: Release Channel Fragmentation

Affected versions span a significant portion of the AI Gateway release cycle: all builds from 18.1.6 up to but not including 19.2.4, the 19.3 series before 19.3.2, and 19.4 before 19.4.1. Per the NVD record, these are the precise semantic ranges. GitLab simultaneously released three patched versions: 19.2.4, 19.3.2, and 19.4.1.

The fragmentation matters for operational management: organizations tracking different release lines must verify which branch they are maintaining. Upgrading to the latest major is insufficient if operating on an intermediate LTS. GitLab's advisory is explicit: "These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately."

An architectural context: the self-hosted AI Gateway is a separate Docker component from the main GitLab instance, typically deployed on customer-owned infrastructure to govern connections to on-premise AI models or meet data sovereignty requirements. This physical separation confines the vulnerability to the self-hosted perimeter, but it also prevents GitLab from patching centrally.

Immediate Actions

Operational steps follow directly from the dossier:

  • Verify presence of the self-hosted AI Gateway: the component is optional; not all Self-Managed installations include it. If not deployed, the vulnerability does not apply.
  • Update to the patch matching your branch: 19.2.4 for the 19.2 line, 19.3.2 for 19.3, 19.4.1 for 19.4. Skipping intermediate unpatched releases does not mitigate risk.
  • Confirm GitLab.com or GitLab Dedicated are not involved: hosted customers are already protected; no action is required on those environments.
  • Review any direct outreach received: GitLab contacted self-hosted customers directly prior to publication. Check communications from recent weeks for additional instructions.

The AI Infrastructure Blind Spot: When AI Middleware Becomes a Target

A broader reading emerges from this incident. GitLab's AI Gateway is not the core application; it is specialized middleware, often managed by teams distinct from traditional application security. The hype around AI-assisted development has accelerated adoption of this infrastructure without security controls keeping pace.

The documented vulnerability exemplifies a pattern we risk seeing repeated: the prompt template, conceptually a "simple" structured text format, becomes a code execution vector when the parser fails to neutralize malicious input. The sandbox meant to isolate the rendering engine from system privileges is bypassed not with a complex exploit chain, but with a malformed flow configuration.

The dossier does not confirm in-the-wild exploitation for CVE-2026-90970, nor does it provide a public proof-of-concept. However, the combination of authentication with relatively accessible privileges (Duo Agent Platform access, not administrator) and no required user interaction lowers the theoretical exploit barrier. GitLab's preventive outreach suggests an internal assessment of elevated risk for the self-hosted population.

Frequently Asked Questions

Is my GitLab Self-Managed instance vulnerable without the AI Gateway?
No. The vulnerability is specific to the self-hosted AI Gateway service. The core GitLab EE/CE instance is not affected.

What is the difference between the self-hosted AI Gateway and AI features on GitLab.com?
On GitLab.com and GitLab Dedicated, the AI Gateway is managed by GitLab and has already been patched. Customers take no action. The self-hosted AI Gateway is deployed on customer infrastructure for use cases requiring local data control or proprietary models.

Why is CVSS 9.9 with PR:L (low privileges) considered so severe?
Because the UI:N (no user interaction) and S:C (changed scope) parameters amplify impact. An attacker with valid credentials can automate exploitation without social engineering, and the sandbox escape can propagate beyond the initial component.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. nvd.nist.gov
  3. cisa.gov
  4. docs.gitlab.com