Skip to main content
CybersecurityVulnerability Management

GitLab Fixes 9.9 Flaw in AI Gateway That Enables Command Execution

Brightly-lit server room interior with AI Gateway device centered.

GitLab rated CVE-2026-90970 critical on October 2, assigning it a CVSS score of 9.9 out of 10.

The AI Gateway prompt-template escape (CVE-2026-90970)

GitLab's advisory says the newly disclosed flaw is in the prompt template of a custom flow. Custom flows are AI-powered workflows created on the Duo Agent Platform to automate multi-step tasks. According to the advisory, a logged-in user with Duo Agent Platform access could "escape the prompt template sandbox via a specially crafted flow configuration," which could lead to arbitrary command execution on the AI Gateway.

The advisory does not enumerate the precise conditions required for the attack and names no user role beyond Duo Agent Platform access. GitLab credited the HackerOne reporter invisiblemeerkat for the finding.

Who needs to act: self-hosted gateways versus GitLab-run gateways

The vulnerability affects only organizations that host their own AI Gateway. GitLab runs AI Gateways for its customers and said it has already fixed those instances; customers using GitLab.com, GitLab Dedicated, and self-managed GitLab instances that rely on a GitLab-hosted gateway do not need to take action. The advisory warns that self-managed customers who choose to host their own gateway should update immediately, and GitLab said it sent those instructions to affected customers before publishing the public advisory.

Affected and fixed versions; update steps

GitLab lists fixed gateway releases as 19.2.4, 19.3.2, and 19.4.1. No fixed version is provided below 19.2.4, which places every gateway release from 18.1.6 through the entire 19.1 line inside the affected range. As of October 2, GitLab's maintenance policy also lists 19.4, 19.3, and 19.2 as the releases that receive security fixes—the same three lines that received the gateway fix.

The advisory reiterates that the AI Gateway is distributed as its own Docker image or Helm chart and carries its own update steps. For Docker deployments, administrators should stop and remove the running container, pull the new image tag, and run the updated container (the advisory gives an example image tag, self-hosted-v19.4.1-ee). Helm deployments apply the update by setting the new tag in the chart's image setting.

GitLab's advisory lists no workaround for gateways that cannot be updated immediately, and it provides no mechanism in the advisory to check whether a gateway was attacked before it was updated.

Operational risks: JWT signing keys and model connectivity

The advisory highlights what a self-hosted gateway holds and connects to: signing keys for JSON Web Tokens (JWT) that GitLab's install guide says must be treated as sensitive credentials, plus connections to the GitLab instance and an organization's AI model providers. Because the flaw could permit arbitrary command execution on the gateway, the advisory implicitly links exploitation risk to those sensitive keys and to the gateway's network relationships with GitLab and external AI providers.

Context: related February fix and technical class (CWE-1336)

GitLab noted a prior gateway remediation in February under CVE-2026-1868, which was also rated 9.9. In that earlier fix a logged-in user could reach the vulnerability through a crafted flow definition and the impact could include denial of service or code execution on the gateway. Both the February flaw and the current CVE-2026-90970 are described as template engine weaknesses in the same class, CWE-1336. The new advisory does not mention the February flaw directly.

CISA added an assessment to the CVE record on October 2 that lists exploitation as "none." The CVE record system also holds other possible assessments—public proof of concept or active exploitation—but CISA's entry for this CVE records no exploitation to date. The advisory itself does not say whether the flaw has been used in attacks.

For administrators running self-hosted AI Gateways the immediate concrete steps are straightforward and limited: apply the fixed gateway image (19.2.4, 19.3.2, or 19.4.1) following Docker or Helm update procedures. Beyond patching, the advisory leaves two operational questions unaddressed that organizations will want answered by their vendors or incident responders: whether a gateway can be audited to determine past compromise, and whether the fixed gateway images are compatible across GitLab minor versions—GitLab's install guide recommends using a gateway image that matches the GitLab minor release, but the advisory does not state whether the 19.2.4+ gateway images will work with older GitLab releases or whether fixes for older lines are planned.

Link to original advisory: https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html