GitLab Fixes AI Gateway Sandbox Escape Enabling Command Execution

GitLab fixed a critical AI Gateway sandbox escape that could let authenticated users execute commands. Self-hosted gateways should upgrade to patched releases.

GitLab Fixes AI Gateway Sandbox Escape Enabling Command Execution
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

GitLab has disclosed a critical vulnerability in its self-hosted AI Gateway that could allow a qualified, authenticated user to execute arbitrary commands on the gateway host.

The flaw, tracked as CVE-2026-90970, affects several GitLab AI Gateway release lines. Exploitation requires an account with Duo Agent Platform access and a specially constructed flow configuration capable of escaping the prompt-template sandbox.

GitLab disclosed the issue on October 2, 2026. Customers running their own AI Gateway should upgrade immediately, while deployments using a GitLab-operated gateway are already protected, according to the company.

Template injection crosses the sandbox boundary

GitLab AI Gateway supplies the backend connectivity required by AI-native GitLab Duo capabilities. It can be operated by GitLab or deployed separately inside a customer-controlled environment through GitLab Duo Self-Hosted.

CVE-2026-90970 resides in the handling of prompt templates. Under the conditions described in the NVD record, an authenticated user with Duo Agent Platform access can submit a crafted flow configuration that breaks out of the intended template sandbox.

A successful escape results in arbitrary command execution on the AI Gateway. The available reporting does not describe the additional conditions needed beyond authentication, Duo Agent Platform access and control over the malicious flow configuration.

NVD classifies the vulnerability as CWE-1336, or improper neutralization of special elements used in a template engine. Its GitLab CNA vector is:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

That vector describes a network-reachable, low-complexity attack requiring low privileges but no user interaction. The scope changes after exploitation, with high potential impact to confidentiality, integrity and availability.

The Hacker News reports that GitLab assigned the vulnerability a severity score of 9.9 out of 10. The NVD page displays the CNA vector but, as of October 2, 2026, does not provide a separate NIST base score.

HackerOne researcher invisiblemeerkat was credited with reporting the flaw.

Exact affected and fixed AI Gateway releases

CVE-2026-90970 affects the following GitLab AI Gateway versions:

  • 18.1.6 and later, before 19.2.4
  • 19.3 before 19.3.2
  • 19.4 before 19.4.1

GitLab has released these corrected versions:

  • 19.2.4
  • 19.3.2
  • 19.4.1

These numbers refer specifically to AI Gateway releases. Administrators should not assume they identify equivalent GitLab application versions.

That distinction matters because the gateway is distributed and updated separately. It can run from its own Docker image or through a Helm chart. For Docker installations, the reported upgrade process involves stopping and removing the existing container, pulling the corrected image and starting the replacement. An example fixed image tag is:

self-hosted-v19.4.1-ee

For Helm-based installations, operators must change the image tag configured in the chart and deploy the updated release.

GitLab’s installation guidance calls for matching the AI Gateway image to the GitLab minor version. The available advisory does not clarify whether AI Gateway 19.2.4 can be paired with GitLab 19.1 or an earlier application release, or whether corrected gateway builds will be supplied for older branches. As of October 2, 2026, GitLab’s maintenance policy listed 19.2, 19.3 and 19.4 as receiving security fixes.

Administrators facing a version-alignment question should verify compatibility before changing branches, but they should not leave an exposed vulnerable gateway running while evaluating the upgrade path.

Only self-hosted gateways require customer remediation

The exposure depends on who operates the AI Gateway.

GitLab said the gateways it manages were already protected. That category includes gateways serving:

  • GitLab.com
  • GitLab Dedicated
  • Self-managed GitLab instances configured to use GitLab’s hosted gateway

Customers using those services do not need to patch the gateway themselves.

The required action applies to organizations operating a separate self-hosted AI Gateway. GitLab strongly recommended that those customers install one of the fixed versions immediately. According to BleepingComputer’s reporting, GitLab also contacted affected self-hosted customers directly before publishing the advisory.

A compromised gateway could occupy a sensitive position within an organization’s AI architecture. The service connects to the GitLab instance and to configured AI model providers. It also stores JWT signing keys, which GitLab’s installation documentation treats as sensitive credentials.

Self-hosting is intended in part to keep AI prompts and responses inside the customer’s environment. Command execution on that gateway could therefore expose systems and data involved in those internal processing paths, depending on the gateway’s permissions and network placement.

Patching is the only documented remediation in the available advisory

Operators should first establish whether their GitLab environment uses a GitLab-hosted gateway or a separately managed instance. Those running a self-hosted gateway should then identify its actual image or chart version and upgrade to 19.2.4, 19.3.2 or 19.4.1, as appropriate for the maintained release line.

The advisory, as described by The Hacker News, did not provide an alternative workaround for installations that could not yet be upgraded. It also did not offer a specific procedure for determining whether exploitation occurred before patching.

No indicators of compromise are included in the material reviewed for this report. That does not establish that no additional indicators or investigative guidance have been published elsewhere.

The supplied reporting also does not establish exploitation of CVE-2026-90970. The advisory did not say that attacks had occurred, while a CISA assessment added to the CVE record on October 2, 2026 reportedly marked exploitation as “none.” That assessment should not be confused with a separate, actively exploited GitLab vulnerability added to CISA’s Known Exploited Vulnerabilities catalog.

Earlier AI Gateway flaw shared the same weakness class

CVE-2026-90970 is not the first high-severity template-processing problem reported in GitLab AI Gateway.

An earlier issue, CVE-2026-1868, affected the Duo Workflow Service component. Crafted Duo Agent Platform Flow definitions could trigger insecure expansion of user-controlled template data, causing denial of service or code execution on the gateway.

That vulnerability also carried a 9.9 score, the same CNA vector and the CWE-1336 classification:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-1868 affected specified AI Gateway builds across the 18.1.6 through 18.8.0 release range and was corrected in 18.6.2, 18.7.1 and 18.8.1. The available coverage says it was fixed “in February,” without specifying a year.

Although the two vulnerabilities share a weakness category and similar attack requirements, they remain separate defects with different affected and fixed versions. Administrators should validate their installations against both records rather than treating the latest update as evidence that every older deployment path was previously safe.

A separate GitLab server flaw is under active exploitation

CVE-2026-90970 must also be distinguished from CVE-2026-85706, a CVSS 10 path-traversal vulnerability in GitLab Community Edition and Enterprise Edition.

CVE-2026-85706 can, under certain conditions, let an unauthenticated attacker read arbitrary files through the repository commits API because of improper path confinement and missing authentication enforcement. Its affected lines are:

  • 18.7 before 18.11.12
  • 19.0 before 19.0.9
  • 19.1 before 19.1.8
  • 19.2 before 19.2.6
  • 19.3 before 19.3.2

CISA added CVE-2026-85706 to the KEV catalog on September 11, 2026, based on evidence of active exploitation. The remediation deadline for U.S. federal agencies was September 14, 2026.

CISA directed agencies to apply vendor mitigations while complying with BOD 26-04 and its “Forensics Triage Requirements.” For applicable cloud services, agencies must follow the relevant BOD 26-04 guidance or discontinue use when mitigations are unavailable. They are also responsible for evaluating each asset’s internet exposure and meeting the directive’s patching requirements.

That confirmed exploitation applies to CVE-2026-85706, not the newly disclosed AI Gateway vulnerability. Organizations operating GitLab infrastructure should nevertheless assess both layers: the GitLab CE/EE server and any independently deployed AI Gateway.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →