- A specially crafted flow configuration could let an authenticated user with Duo Agent Platform access escape the prompt-template sandbox and execute commands on an AI Gateway.
- GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue.
- CISA’s CVE record assessment listed exploitation as none.
On this page
A crafted flow could escape the sandbox
Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt-template sandbox, leading to arbitrary command execution on the AI Gateway.
GitLab identified the issue as CVE-2026-90970, an improper-neutralization issue in a custom flow prompt template.
Self-hosted gateways are affected
GitLab lists affected AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.
GitLab-hosted gateways have a deployed fix. Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance with a GitLab-hosted AI Gateway are protected and do not need to take action.
| Affected line | Fixed version |
|---|---|
| 18.1.6 before 19.2.4 | 19.2.4 |
| 19.3 before 19.3.2 | 19.3.2 |
| 19.4 before 19.4.1 | 19.4.1 |
GitLab disclosed the issue on Oct 2
GitLab said it disclosed the vulnerability on Oct 2, rated it critical, and assigned it a CVSS score of 9.9 out of 10. The Hacker News also published its coverage on Oct 2, 2026.
GitLab said it had conducted targeted outreach to self-hosted AI Gateway customers before publishing its release post and credited invisiblemeerkat with responsibly disclosing the issue.
A self-hosted gateway holds JSON Web Token signing keys that GitLab says must be treated as sensitive credentials. GitLab also fixed CVE-2026-1868 in February and rated that gateway flaw 9.9.
How we checked this story
| Claim | Source | Status |
|---|---|---|
| GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1. | GitLab | Confirmed |
| GitLab fixed its hosted AI Gateways, protecting customers using GitLab-hosted gateways without requiring action. | GitLab | Confirmed |
| Under certain conditions, an authenticated user with Duo Agent Platform access could escape the prompt-template sandbox through a specially crafted flow configuration. | GitLab | Confirmed |
| The vulnerability affects AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. | GitLab | Confirmed |
| GitLab identified the vulnerability as CVE-2026-90970. | GitLab | Confirmed |
| GitLab conducted targeted outreach to self-hosted AI Gateway customers before publishing the release post. | GitLab | Confirmed |
| GitLab credited invisiblemeerkat with responsibly disclosing the vulnerability. | GitLab | Confirmed |
| CISA’s CVE record assessment listed exploitation as none. | CISA, via The Hacker News | Attributed |
| GitLab said the vulnerability was disclosed on October 2. | GitLab, via The Hacker News | Attributed |
| The Hacker News said helm deployments should set the new image tag in the chart’s image setting. | The Hacker News | Attributed |
| GitLab said a self-hosted gateway holds JSON Web Token signing keys that must be treated as sensitive credentials. | GitLab, via The Hacker News | Attributed |
| GitLab fixed another gateway flaw, CVE-2026-1868, in February and rated it 9.9. | GitLab, via The Hacker News | Attributed |
| The Hacker News said both flaws are template-engine weaknesses classified as CWE-1336. | The Hacker News | Attributed |
| The Hacker News published its story on Oct 2, 2026. | The Hacker News | Confirmed |
Could not verify
- Whether the vulnerability was exploited in the wild is not established.
- How many installations or customers were affected is not established.
- Whether the vulnerability has a public proof of concept is not established.
- Whether older gateway lines will receive fixes is not established.
- Whether a vulnerable gateway was attacked before updating is not established.
What to do now
- Self-managed customers with self-hosted AI Gateway installations: “update to one of these versions immediately.
FAQ
Who disclosed the vulnerability?
GitLab credited invisiblemeerkat with responsibly disclosing the issue.
Do GitLab-hosted gateway users need to update?
No. GitLab said customers using GitLab-hosted AI Gateways are protected and do not need to take action.



