Skip to main content
CybersecurityVulnerability Management

GitLab patches RCE flaw in AI Gateway service

Modern server room with equipment racks, servers, and gateway device surrounded by cables and networking gear.

CVE-2026-90970 is a critical remote-code-execution flaw in GitLab’s AI Gateway that, if left unpatched, could allow an attacker to run arbitrary commands on vulnerable instances.

CVE-2026-90970 and how it works

GitLab says the flaw stems from an “improper neutralization weakness” in the AI Gateway prompt template sandbox. In a Friday advisory, the company described the chain: an authenticated user who holds Duo Agent Platform access can escape the prompt template sandbox by supplying a “specially crafted flow configuration,” which can then lead to arbitrary command execution on the AI Gateway.

GitLab’s advisory emphasizes that the risk is not limited to highly privileged accounts: attackers with basic privileges plus Duo Agent Platform access can trigger the condition on unpatched self-hosted instances.

GitLab’s fixes and recommended actions

To address the problem for self-hosted deployments, GitLab released versions 19.2.4, 19.3.2, and 19.4.1. “These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately,” the company wrote in the advisory.

GitLab also said it conducted targeted outreach to Self-Hosted AI Gateway customers prior to the release post and urged those customers to upgrade vulnerable instances as soon as possible. Customers using a GitLab-hosted AI Gateway — the cloud instance GitLab operates for GitLab.com, GitLab Self-Managed, and GitLab Dedicated — are already protected and “do not need to take action.”

Who runs AI Gateway and who is affected

AI Gateway is the service that provides access to AI-native GitLab Duo features. While GitLab operates a cloud-based AI Gateway used by its hosted offerings, organizations can also deploy their own AI Gateway instances via GitLab Duo Self-Hosted on GitLab Self-Managed. The vulnerability and the associated patches therefore split affected parties into two clear groups: self-hosted AI Gateway operators (who must update their installations) and customers of GitLab’s hosted AI Gateway (who the company says are already protected).

Context: recent GitLab flaws and CISA action

This advisory follows a separate, high-severity fix disclosed last month. GitLab patched a maximum-severity path traversal vulnerability, CVE-2026-85706, in GitLab Community Edition and Enterprise Edition; that bug allowed unauthenticated attackers to read sensitive data such as credentials and other secrets from vulnerable servers.

One day after that disclosure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its list of actively exploited flaws and, pursuant to Binding Operational Directive 26-04, gave federal agencies three days to secure affected systems. Since November 2021, CISA has tagged five GitLab vulnerabilities as abused in the wild, including one exploited by ransomware gangs.

What this means for GitLab Self-Managed customers, GitLab-hosted customers, and federal agencies

  • GitLab Self-Managed customers running self-hosted AI Gateway: GitLab has released 19.2.4, 19.3.2, and 19.4.1 and has urged immediate upgrades; targeted outreach to those customers was conducted before the release post.
  • GitLab-hosted customers (GitLab.com, Self-Managed hosted on GitLab Dedicated): Per GitLab, hosted AI Gateway instances are already protected and “do not need to take action.”
  • Federal agencies and organizations subject to CISA directives: The rapid addition of a prior GitLab flaw (CVE-2026-85706) to CISA’s actively exploited list and the three-day remediation mandate under BOD 26-04 illustrates the speed and regulatory attention such GitLab vulnerabilities can attract; agencies that must follow CISA directives have a recent precedent for expedited response.

GitLab’s platform reaches a large audience — the company says its DevSecOps platform has over 30 million registered users and is used by more than 50% of Fortune 100 companies, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS — which helps explain the urgency in patching and in communicating directly with affected self-hosted operators.

GitLab has fixed the code and issued new versions; the remaining, concrete step for exposed organizations is technical: update to one of the released Self-Hosted AI Gateway versions immediately or confirm reliance on GitLab’s hosted gateway where no action is required. How quickly that happens in large, self-managed environments — and whether any unreported exploit attempts affected unpatched instances before GitLab’s remediation and outreach — are the practical questions left to be answered.

Original reporting: https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/