GitLab Patches Critical AI Gateway Vulnerability That Could Allow Command Execution on Self-Hosted Gateways

Views: 63 views

545/69 Monday, October 5, 2026

GitLab has released patches for a Critical vulnerability in GitLab AI Gateway, tracked as CVE-2026-90970 with a CVSS score of 9.9. The vulnerability could allow an authenticated user with access to the Duo Agent Platform to execute commands on the AI Gateway. GitLab disclosed the vulnerability on October 2, 2026, and fixed it in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1. The issue was reported through HackerOne by a researcher known as invisiblemeerkat.

The vulnerability is related to the handling of Custom Flow Prompt Templates in AI Gateway. A user with access to the Duo Agent Platform may be able to submit a specially crafted Flow Configuration to escape the Prompt Template Sandbox and execute commands on the host running the AI Gateway. GitLab has not disclosed further technical details about the exact exploitation requirements or whether additional privileges are needed beyond access to the Duo Agent Platform. AI Gateway acts as an intermediary layer between GitLab Duo and AI models by receiving requests from GitLab, preparing prompts, and communicating with the underlying large language model (LLM).

GitLab stated that it has already patched its hosted AI Gateway infrastructure. Therefore, customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-managed Gateway do not need to take additional action. Organizations running a self-hosted GitLab AI Gateway should update immediately. Affected versions include 18.1.6 through 19.2.3, which should be upgraded to 19.2.4; versions 19.3.0 through 19.3.1, which should be upgraded to 19.3.2; and version 19.4.0, which should be upgraded to 19.4.1. GitLab has not stated that the vulnerability has been exploited in real-world attacks and has not released a Proof-of-Concept or exploitation steps. However, because AI Gateway may handle authentication-related information such as JSON Web Token signing and validation keys through environment variables, organizations operating self-hosted deployments should apply the update promptly to reduce the risk of the Gateway being used as an entry point into infrastructure associated with AI services and organizational authentication systems.

Source: https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html