GitLab AI Gateway CVE-2026-90970: a prompt template runs code
GitLab fixed a CVSS 9.9 sandbox escape in its self-hosted AI Gateway on October 2. A crafted Duo flow runs commands on your server. Patch to 19.4.1.
If you host your own GitLab AI Gateway, this one is yours. GitLab AI Gateway CVE-2026-90970 is a CVSS 9.9 flaw where a crafted prompt template in a custom Duo flow escapes its sandbox and runs arbitrary commands on the gateway. The attacker needs a login and Duo Agent Platform access. That's it. GitLab shipped fixed gateway builds on October 2.
What actually happened
GitLab's patch release for AI Gateway 19.4.1 closes an improper neutralization bug in the prompt template of a custom flow. An authenticated user with Duo Agent Platform access can submit a specially crafted flow configuration, break out of the template sandbox, and execute commands on the AI Gateway host. GitLab scores it 9.9: network-reachable, low complexity, low privileges, and scope change. That last part means the damage leaves the component.
Affected: AI Gateway 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Fixed: 19.2.4, 19.3.2 and 19.4.1. There is no listed workaround.
Who doesn't need to act: GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway. Only shops running their own gateway are exposed. The Hacker News reports no known exploitation yet, and notes this is the second 9.9 in the same class this year after CVE-2026-1868 in February.
Why it matters for your business
Teams self-host the AI Gateway for good reasons: data residency, a self-hosted model, keeping source code off a vendor's inference path. We recommend it often. But self-hosting moves the patch job to you, and most shops patch GitLab itself while the gateway sits on a separate box that nobody tracks.
Prompt templates are code now. A flow config is an input that reaches an interpreter. Treat who can author flows the way you treat who can edit CI pipelines. "Any developer with a Duo seat" is too wide.
The gateway holds the good keys. It talks to your model providers and your GitLab instance. Command execution there means stolen API keys, tampered agent workflows, and a pivot point into the rest of your network.
Patch, then check. Upgrade to 19.4.1 (or 19.3.2 / 19.2.4 on older lines). Then rotate the model-provider credentials the gateway stores. Then review which users can create custom flows.
Key takeaways
- CVE-2026-90970 is a CVSS 9.9 prompt-template sandbox escape in self-hosted GitLab AI Gateway, leading to command execution
- Attacker needs an account with Duo Agent Platform access and a crafted custom flow configuration
- Affected: 18.1.6–19.2.3, 19.3.0–19.3.1, 19.4.0. Fixed: 19.2.4, 19.3.2, 19.4.1. No workaround
- GitLab.com, Dedicated, and GitLab-hosted gateway users need no action
- After patching, rotate gateway-stored model API keys and limit who can author custom flows
Self-hosted AI with nobody owning the patches? We set up private AI infrastructure with a named owner, a version inventory, and a patch path for every box, the gateway included. See what we build, or send us your current setup.
Sources: GitLab AI Gateway 19.4.1 patch release, The Hacker News.
- #gitlab
- #cve-2026-90970
- #ai-gateway
- #duo-agent-platform
- #patch-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read itSupabase buys Turso: agents now make 70% of new databases
Supabase raised $150M and is acquiring Turso, the SQLite-based database for AI agents. 70% of its new databases come from agents. Who owns yours?
Read it