Critical

GitLab, AI Gateway, Duo, CVE-2026-90970, RCE, prompt injection, sandbox escape, self-hosted

GitLab AI Gateway CVE-2026-90970: Critical RCE

GitLab AI Gateway CVE-2026-90970 (CVSS 9.9) lets a Duo user escape the prompt sandbox to run commands on self-hosted GitLab. Fixed in 19.2.4/19.3.2/19.4.1.

GitLab CVE-2026-90970 is a critical flaw (CVSS 9.9) in the GitLab AI Gateway, the service behind GitLab Duo, that lets an authenticated user with Duo Agent Platform access escape the prompt-template sandbox through a crafted flow configuration and run arbitrary commands on self-hosted AI Gateway servers. GitLab fixed it in versions 19.2.4, 19.3.2, and 19.4.1, so self-managed customers running the AI Gateway should upgrade now.

The GitLab AI Gateway is the component that provides GitLab Duo's AI features; GitLab runs it in the cloud for GitLab.com and Dedicated customers, while self-managed users can deploy their own self-hosted instance. A command-execution bug there matters because the gateway sits next to source code, CI/CD, and developer credentials, so running commands on it is a foothold inside the software factory. According to The Hacker News and BleepingComputer, GitLab conducted targeted outreach to self-hosted AI Gateway customers before disclosing publicly on October 2, 2026.

The mechanism is an improper-neutralization weakness in how the gateway handles flow configurations. An attacker with Duo Agent Platform access supplies a specially crafted flow configuration that escapes the prompt-template sandbox, turning a feature meant to shape prompts into a path for arbitrary command execution. It requires authentication and Duo access, which lowers the external attack surface, but on a self-hosted gateway an authenticated insider or a compromised developer account becomes a route to code execution on the AI service. Cloud-hosted GitLab.com and Dedicated instances are operated by GitLab; the urgent action is for self-managed deployments.

What is CVE-2026-90970 and why does the AI angle matter?

CVE-2026-90970 is a sandbox-escape-to-command-execution flaw in the GitLab AI Gateway. The AI-specific part is the attack surface: a prompt-template and flow-configuration system, built to let users customize how Duo's agents behave, became the thing an attacker abuses to break out and run commands. It is a pattern worth noting across AI tooling, the configuration and templating layers that make agents flexible are also new, under-scrutinized places for injection and sandbox escapes. For background on why these AI-service connection points are such a sharp edge, see our explainer on MCP security and its risks.

Which GitLab versions are affected and fixed?

Branch

Affected

Fixed

19.2.x

before 19.2.4

19.2.4

19.3.x

before 19.3.2

19.3.2

19.4.x

before 19.4.1

19.4.1

Upgrade to the fixed release for your branch. Self-managed customers running the AI Gateway should prioritize this, and in the meantime review who holds Duo Agent Platform access, since the flaw requires that access to exploit. There is no evidence of in-the-wild exploitation at disclosure, which makes this the window to patch rather than a reason to wait.

Is CVE-2026-90970 being exploited?

No in-the-wild exploitation was reported at disclosure, and GitLab moved proactively by notifying self-hosted AI Gateway customers before going public. That said, a CVSS 9.9 command-execution flaw in a developer-platform component is exactly the kind of bug that draws attention once details circulate, and the authentication requirement is a weak barrier in environments where developer accounts are plentiful and sometimes compromised.

Our read

This is the AI-tooling version of a familiar story: a flexible configuration surface, here prompt templates and agent flows, becomes an execution path because the sandbox around it was not as tight as assumed. As teams add AI gateways and agent platforms to their stacks, those components inherit every old rule about input handling and privilege, then add new ones specific to prompts and flows. The verifiable-by-design takeaway is to treat the AI gateway as high-value attack surface inside your software factory: confirm who can reach its configuration features, keep it patched, and test whether a crafted flow actually stays inside its sandbox on your build rather than trusting that it does. The glue between your developers and their models is now code-execution-adjacent, and it deserves the same scrutiny as the code itself.

Reporting by The Hacker News and BleepingComputer; CVSS 9.9, affected versions, and fix per GitLab's security advisory. Sources linked above.

Frequently asked questions

What is CVE-2026-90970?
It is a critical vulnerability (CVSS 9.9) in the GitLab AI Gateway where an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox via a crafted flow configuration and execute arbitrary commands on self-hosted servers.

Which GitLab versions fix CVE-2026-90970?
GitLab 19.2.4, 19.3.2, and 19.4.1. Affected versions are 19.2.x before 19.2.4, 19.3.x before 19.3.2, and 19.4.x before 19.4.1.

Who is at risk from CVE-2026-90970?
Self-managed GitLab customers running their own AI Gateway. Cloud-hosted GitLab.com and Dedicated instances are operated by GitLab. Exploitation requires an authenticated user with Duo Agent Platform access.

Is CVE-2026-90970 being exploited?
No in-the-wild exploitation was reported at disclosure. GitLab notified self-hosted AI Gateway customers before public disclosure on October 2, 2026, and the fix is available now.

Writing your own code with AI? The same bug classes surface there too. Scan your code free with Argus ›
Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.
AI CODE SECURITY
Catch the bug before it ships
Argus scans your repos for the vulnerability classes behind today's CVEs.
›Prioritized by real exploit data
›Connect a repo in minutes
Run a free scan
Live NVD · EPSS · CISA KEV