// AI threat desk · 3 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalRCECVSS 9.9

GitLab AI Gateway flaw could execute commands from crafted flow

GitLab said on Oct 2 that it disclosed the critical AI Gateway vulnerability and rated it 9.9 out of 10.

stock image, not from the event
File photo: stock image, not from the event. Photo: Markus Spiske / rawpixel (CC0)
Key takeaways
  • A specially crafted flow configuration could let an authenticated user with Duo Agent Platform access escape the prompt-template sandbox and execute commands on an AI Gateway.
  • GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue.
  • CISA’s CVE record assessment listed exploitation as none.
On this page

A crafted flow could escape the sandbox

Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt-template sandbox, leading to arbitrary command execution on the AI Gateway.

GitLab identified the issue as CVE-2026-90970, an improper-neutralization issue in a custom flow prompt template.

Self-hosted gateways are affected

GitLab lists affected AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.

GitLab-hosted gateways have a deployed fix. Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance with a GitLab-hosted AI Gateway are protected and do not need to take action.

Affected lineFixed version
18.1.6 before 19.2.419.2.4
19.3 before 19.3.219.3.2
19.4 before 19.4.119.4.1

GitLab disclosed the issue on Oct 2

GitLab said it disclosed the vulnerability on Oct 2, rated it critical, and assigned it a CVSS score of 9.9 out of 10. The Hacker News also published its coverage on Oct 2, 2026.

GitLab said it had conducted targeted outreach to self-hosted AI Gateway customers before publishing its release post and credited invisiblemeerkat with responsibly disclosing the issue.

A self-hosted gateway holds JSON Web Token signing keys that GitLab says must be treated as sensitive credentials. GitLab also fixed CVE-2026-1868 in February and rated that gateway flaw 9.9.

How we checked this story
ClaimSourceStatus
GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.GitLabConfirmed
GitLab fixed its hosted AI Gateways, protecting customers using GitLab-hosted gateways without requiring action.GitLabConfirmed
Under certain conditions, an authenticated user with Duo Agent Platform access could escape the prompt-template sandbox through a specially crafted flow configuration.GitLabConfirmed
The vulnerability affects AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.GitLabConfirmed
GitLab identified the vulnerability as CVE-2026-90970.GitLabConfirmed
GitLab conducted targeted outreach to self-hosted AI Gateway customers before publishing the release post.GitLabConfirmed
GitLab credited invisiblemeerkat with responsibly disclosing the vulnerability.GitLabConfirmed
CISA’s CVE record assessment listed exploitation as none.CISA, via The Hacker NewsAttributed
GitLab said the vulnerability was disclosed on October 2.GitLab, via The Hacker NewsAttributed
The Hacker News said helm deployments should set the new image tag in the chart’s image setting.The Hacker NewsAttributed
GitLab said a self-hosted gateway holds JSON Web Token signing keys that must be treated as sensitive credentials.GitLab, via The Hacker NewsAttributed
GitLab fixed another gateway flaw, CVE-2026-1868, in February and rated it 9.9.GitLab, via The Hacker NewsAttributed
The Hacker News said both flaws are template-engine weaknesses classified as CWE-1336.The Hacker NewsAttributed
The Hacker News published its story on Oct 2, 2026.The Hacker NewsConfirmed

Could not verify

  • Whether the vulnerability was exploited in the wild is not established.
  • How many installations or customers were affected is not established.
  • Whether the vulnerability has a public proof of concept is not established.
  • Whether older gateway lines will receive fixes is not established.
  • Whether a vulnerable gateway was attacked before updating is not established.

What to do now

  1. Self-managed customers with self-hosted AI Gateway installations: “update to one of these versions immediately.

FAQ

Who disclosed the vulnerability?

GitLab credited invisiblemeerkat with responsibly disclosing the issue.

Do GitLab-hosted gateway users need to update?

No. GitLab said customers using GitLab-hosted AI Gateways are protected and do not need to take action.

Sources

  1. GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1 | GitLab Docs, GitLabPrimary
  2. GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers, The Hacker News
Explore with AI