Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

October 3, 2026

GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features.

The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early guidance on the required updates.

GitLab AI Gateway Vulnerability

The vulnerability involves improper handling of custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could submit a specially crafted flow configuration that escapes the prompt template sandbox. Successful exploitation could then allow arbitrary commands to run on the AI Gateway.

A sandbox is meant to keep template processing within a controlled boundary. In this case, GitLab says crafted input could cross that boundary and reach command execution. The disclosed impact is therefore more serious than changing an AI response: it could affect the service that processes AI requests.

The published CVSS vector describes a network-accessible attack with low complexity, low privileges, and no required user interaction. It assigns high impact to confidentiality, integrity, and availability. However, this is not an unauthenticated flaw; the attacker needs a valid account with Duo Agent Platform access.

GitLab credited security researcher invisiblemeerkat with responsibly reporting the issue. The advisory does not provide an exploit payload, identify the template engine involved, or report active exploitation. Those limits matter: the release confirms a critical security weakness, but it does not establish that attackers have already used it.

Affected AI Gateway releases include versions starting at 18.1.6 and earlier than 19.2.4, the 19.3 branch before 19.3.2, and the 19.4 branch before 19.4.1. These version ranges apply to the AI Gateway component. Administrators should check the gateway deployment rather than rely only on their main GitLab instance version.

GitLab has already deployed the fix to its hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-hosted AI Gateway are protected and need no action for this issue. Customers operating their own affected AI Gateway must install the update themselves.

The distinction matters because GitLab’s self-hosted AI setup lets organizations manage requests to their chosen model backends within their own environment. Cybersecurity News previously covered a separate GitLab Duo prompt injection vulnerability involving source code exposure. That earlier issue should not be confused with this gateway sandbox escape.

Administrators should follow GitLab’s AI Gateway installation and upgrade documentation to deploy a patched image. For Docker installations, GitLab instructs users to stop and remove the existing container, then pull and run the new image with the correct environment variables. Verify the deployed image digest and run the available health checks afterward.

For Kubernetes and Helm deployments, GitLab warns that cached images can prevent updated code from being pulled. Its guidance recommends image digests or an appropriate pull policy. Administrators should also restrict unnecessary outbound gateway traffic while preserving required connections. These controls support hardening, but the immediate priority remains installing a fixed AI Gateway release without delay.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Original article can be found here