Menu
VULNERABILITIES & FIXES

CVE-2026-90970: Critical GitLab AI Gateway Flaw Enables Command Execution

Uday Patil Oct 3, 2026 8 min read 5 views
CVE-2026-90970: Critical GitLab AI Gateway Flaw Enables Command Execution

GitLab has released security updates for a critical vulnerability in its AI Gateway that could allow an authenticated attacker to escape a prompt-template sandbox and execute arbitrary commands on affected self-hosted systems.

Tracked as CVE-2026-90970, the vulnerability carries a CVSS v3.1 score of 9.9 out of 10 and affects certain versions of the GitLab Self-Hosted AI Gateway used with GitLab Duo and the Duo Agent Platform.

The flaw can be triggered when an authenticated user with access to the Duo Agent Platform submits a specially crafted flow configuration. Under vulnerable conditions, that configuration can escape the prompt-template sandbox and lead to command execution on the AI Gateway.

Key takeaway: Organizations running their own GitLab AI Gateway should check the deployed version and upgrade immediately to 19.2.4, 19.3.2, 19.4.1, or a later supported release.

What Is CVE-2026-90970?

CVE-2026-90970 is a critical security vulnerability affecting the GitLab AI Gateway.

According to the official GitLab security release, the issue involves improper neutralization in custom flow prompt templates.

Under certain conditions, an authenticated user with access to the Duo Agent Platform can submit a specially crafted flow configuration capable of escaping the prompt-template sandbox.

Successful exploitation can lead to arbitrary command execution on the AI Gateway, making the flaw especially serious for organizations operating self-hosted AI infrastructure.

For broader coverage of high-impact software flaws, patch releases, and enterprise exploitation risks, see our CVE and vulnerability exploits security hub.

Why Is the GitLab AI Gateway Vulnerability Critical?

The GitLab AI Gateway is a standalone service that provides access to AI-native GitLab Duo features.

GitLab can operate the gateway as a hosted service, but organizations can also deploy a self-hosted AI Gateway inside their own infrastructure when using GitLab Duo Self-Hosted.

In a fully self-hosted configuration, the organization manages the gateway, AI models, infrastructure, and security controls itself.

This makes command execution on the gateway particularly serious because the affected service may operate inside a trusted enterprise environment and communicate with internal systems or model infrastructure.

The published CVSS assessment gives CVE-2026-90970 a score of 9.9 out of 10.

The vulnerability has the following characteristics:

  • Network-based attack vector
  • Low attack complexity
  • Low privileges required
  • No additional user interaction required
  • High confidentiality impact
  • High integrity impact
  • High availability impact

However, the flaw is not unauthenticated. GitLab states that exploitation requires an authenticated user with Duo Agent Platform access.

How Could CVE-2026-90970 Be Exploited?

The vulnerability is related to the processing of custom flow prompt templates in the AI Gateway.

An attacker who already has the required Duo Agent Platform access could prepare a specially crafted flow configuration containing input designed to break out of the intended prompt-template sandbox.

The sandbox exists to constrain how template content is interpreted and prevent unsafe execution paths.

If that protection is bypassed, attacker-controlled template data can cross the intended boundary and result in command execution on the underlying AI Gateway.

Important: CVE-2026-90970 requires authenticated access. It should not be described as an unauthenticated remote-code-execution vulnerability.

Which GitLab AI Gateway Versions Are Affected?

GitLab lists the following AI Gateway release ranges as affected:

Affected Version RangeFixed Version
18.1.6 through versions before 19.2.419.2.4
19.3 through versions before 19.3.219.3.2
19.4 through versions before 19.4.119.4.1

Administrators should verify the version of the AI Gateway component itself instead of relying only on the version of the main GitLab instance.

Who Needs to Take Action?

The vulnerability primarily requires action from organizations operating an affected GitLab Self-Hosted AI Gateway.

GitLab strongly recommends that affected self-hosted installations upgrade as soon as possible.

Customers using GitLab-hosted AI Gateway infrastructure do not need to patch the gateway themselves for this specific issue because GitLab states that the fix has already been deployed.

This includes customers using:

  • GitLab.com with a GitLab-hosted AI Gateway
  • GitLab Dedicated with a GitLab-hosted AI Gateway
  • GitLab Self-Managed connected to a GitLab-hosted AI Gateway

Organizations that deploy and maintain their own AI Gateway remain responsible for applying the security update.

What Should Administrators Do Now?

Administrators responsible for GitLab Duo Self-Hosted or another self-managed AI Gateway deployment should prioritize the update.

Recommended actions include:

  1. Confirm whether the organization operates a self-hosted GitLab AI Gateway.
  2. Check the currently deployed AI Gateway version.
  3. Upgrade to version 19.2.4, 19.3.2, 19.4.1, or a later supported release.
  4. Verify that the patched gateway image or package is actually running.
  5. Restart or redeploy the affected service where required.
  6. Run health checks after the upgrade.
  7. Review access to the Duo Agent Platform and remove unnecessary privileges.
  8. Review AI Gateway logs for suspicious flow configurations or unexpected activity.

Administrators should also make sure that containerized or orchestrated deployments are not continuing to use an older cached AI Gateway image.

GitLab-Hosted vs Self-Hosted AI Gateway

GitLab supports both hosted and self-hosted AI Gateway configurations.

With the standard GitLab-hosted option, GitLab manages the AI Gateway infrastructure used to access GitLab Duo features.

Organizations can also deploy their own AI Gateway through GitLab Duo Self-Hosted and connect it to self-hosted language models.

This configuration can help organizations keep request and response data inside their own environment and maintain greater control over their AI infrastructure.

However, that additional control also means the organization is responsible for deploying, maintaining, and securing the gateway.

For broader analysis of security risks affecting AI agents, model gateways, and autonomous systems, see our AI-era threats and agentic security guide.

Why AI Gateways Need Strong Security Controls

AI gateways are becoming an important layer between enterprise applications, AI agents, and large language models.

They can handle authentication, prompt processing, model routing, request transformation, logging, and communication with internal or external AI services.

A vulnerability in this layer can therefore create risks that go beyond an incorrect AI response.

If an attacker gains command execution on the service running the gateway, the impact can potentially extend to the underlying operating environment and other resources accessible from that system.

Organizations should treat AI gateways as privileged infrastructure and apply the same patching, access-control, monitoring, and hardening practices used for other sensitive middleware and application services.

Another Critical GitLab Vulnerability Administrators Should Review

GitLab administrators should also be aware of other recently disclosed GitLab security issues.

Our sister site TechUpdate24 has covered CVE-2026-85706, a critical GitLab file-read vulnerability affecting self-managed GitLab environments.

Reviewing multiple high-impact GitLab vulnerabilities can help administrators confirm that both the main GitLab platform and related AI infrastructure are running supported, patched versions.

CVE-2026-90970 Technical Details

CVE IDCVE-2026-90970
ProductGitLab AI Gateway
SeverityCritical
CVSS v3.19.9 / 10
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
WeaknessCWE-1336
Patch AvailableYes

The published CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The vulnerability is classified under CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine.

Has CVE-2026-90970 Been Exploited in the Wild?

GitLab’s public security release describes the vulnerability, affected versions, and available security updates but does not state that CVE-2026-90970 is being actively exploited in the wild.

Security teams should therefore avoid presenting active exploitation as confirmed unless GitLab or another authoritative source publishes additional evidence.

However, the absence of confirmed exploitation is not a reason to delay patching. The vulnerability has a critical CVSS score and can lead to command execution on affected gateways.

Frequently Asked Questions

What is CVE-2026-90970?

CVE-2026-90970 is a critical GitLab AI Gateway vulnerability that can allow an authenticated Duo Agent Platform user to escape a prompt-template sandbox and execute arbitrary commands on an affected gateway.

What is the CVSS score for CVE-2026-90970?

The vulnerability has a CVSS v3.1 score of 9.9 out of 10, placing it in the Critical severity category.

Does CVE-2026-90970 require authentication?

Yes. GitLab states that exploitation requires an authenticated user with Duo Agent Platform access.

Does exploitation require user interaction?

No additional victim interaction is required once the attacker has the necessary authenticated access.

Which versions fix CVE-2026-90970?

GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the vulnerability.

Are GitLab.com users affected?

GitLab says the security fix has already been deployed to GitLab-hosted AI Gateways. Customers using GitLab.com or another GitLab-hosted gateway configuration do not need to patch the gateway themselves for this specific vulnerability.

Who should patch immediately?

Organizations running an affected GitLab Self-Hosted AI Gateway should upgrade to a fixed version as soon as possible.

Final Takeaway

CVE-2026-90970 is a high-impact GitLab AI Gateway vulnerability because a user with authenticated Duo Agent Platform access could potentially turn a malicious flow configuration into command execution on the gateway.

The risk is particularly important for organizations running self-hosted AI infrastructure, where the gateway may operate inside trusted networks and communicate with internal model services.

GitLab-hosted gateways have already received the security fix, but administrators responsible for affected self-hosted deployments should upgrade immediately and verify that the patched version is actually running.

Stay Updated on Critical Vulnerabilities

AI infrastructure is becoming an increasingly important part of enterprise security, and vulnerabilities in gateways, agents, and model integrations can create risks beyond traditional application flaws.

Follow CyberUpdates365 for verified CVE alerts, vulnerability analysis, AI security updates, patch information, and practical security guidance for administrators and defenders.

Running a self-hosted GitLab AI Gateway? Check your deployed version now and upgrade immediately if it falls within an affected range.

Official Sources

GitLab Security Patch Release:
GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1

GitLab AI Gateway Documentation:
Official GitLab AI Gateway documentation

GitLab Duo Self-Hosted Documentation:
Official GitLab Duo Self-Hosted documentation

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.