Skip to content
Rush Commerce
Software & Dev2 min read

GitLab AI Gateway CVE-2026-90970: a prompt template runs code

GitLab fixed a CVSS 9.9 sandbox escape in its self-hosted AI Gateway on October 2. A crafted Duo flow runs commands on your server. Patch to 19.4.1.

If you host your own GitLab AI Gateway, this one is yours. GitLab AI Gateway CVE-2026-90970 is a CVSS 9.9 flaw where a crafted prompt template in a custom Duo flow escapes its sandbox and runs arbitrary commands on the gateway. The attacker needs a login and Duo Agent Platform access. That's it. GitLab shipped fixed gateway builds on October 2.

What actually happened

GitLab's patch release for AI Gateway 19.4.1 closes an improper neutralization bug in the prompt template of a custom flow. An authenticated user with Duo Agent Platform access can submit a specially crafted flow configuration, break out of the template sandbox, and execute commands on the AI Gateway host. GitLab scores it 9.9: network-reachable, low complexity, low privileges, and scope change. That last part means the damage leaves the component.

Affected: AI Gateway 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Fixed: 19.2.4, 19.3.2 and 19.4.1. There is no listed workaround.

Who doesn't need to act: GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway. Only shops running their own gateway are exposed. The Hacker News reports no known exploitation yet, and notes this is the second 9.9 in the same class this year after CVE-2026-1868 in February.

Why it matters for your business

Teams self-host the AI Gateway for good reasons: data residency, a self-hosted model, keeping source code off a vendor's inference path. We recommend it often. But self-hosting moves the patch job to you, and most shops patch GitLab itself while the gateway sits on a separate box that nobody tracks.

Prompt templates are code now. A flow config is an input that reaches an interpreter. Treat who can author flows the way you treat who can edit CI pipelines. "Any developer with a Duo seat" is too wide.

The gateway holds the good keys. It talks to your model providers and your GitLab instance. Command execution there means stolen API keys, tampered agent workflows, and a pivot point into the rest of your network.

Patch, then check. Upgrade to 19.4.1 (or 19.3.2 / 19.2.4 on older lines). Then rotate the model-provider credentials the gateway stores. Then review which users can create custom flows.

Key takeaways

  • CVE-2026-90970 is a CVSS 9.9 prompt-template sandbox escape in self-hosted GitLab AI Gateway, leading to command execution
  • Attacker needs an account with Duo Agent Platform access and a crafted custom flow configuration
  • Affected: 18.1.6–19.2.3, 19.3.0–19.3.1, 19.4.0. Fixed: 19.2.4, 19.3.2, 19.4.1. No workaround
  • GitLab.com, Dedicated, and GitLab-hosted gateway users need no action
  • After patching, rotate gateway-stored model API keys and limit who can author custom flows

Self-hosted AI with nobody owning the patches? We set up private AI infrastructure with a named owner, a version inventory, and a patch path for every box, the gateway included. See what we build, or send us your current setup.

Sources: GitLab AI Gateway 19.4.1 patch release, The Hacker News.

  • #gitlab
  • #cve-2026-90970
  • #ai-gateway
  • #duo-agent-platform
  • #patch-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.