Skip to content

GitLab patches a critical 9.9 AI Gateway flaw that let Duo users run commands on the server

CVE-2026-90970 lets an authenticated user with Duo Agent Platform access escape the AI Gateway's prompt-template sandbox; only self-hosted gateways need to update.

By VibecodedThis 2 min read
GitLab logo
GitLab (Wikimedia Commons, MIT)

GitLab disclosed a critical vulnerability in its self-hosted AI Gateway on October 2, assigning it a CVSS score of 9.9 out of 10. Tracked as CVE-2026-90970, the flaw lets an authenticated user with Duo Agent Platform access escape a prompt-template sandbox and run arbitrary commands on the gateway itself.

The bug lives in the prompt templates behind custom flows. Custom flows are AI-powered workflows users build inside Duo Agent Platform to automate multi-step work, and the AI Gateway renders them using prompt templates that are meant to be sandboxed. In GitLab's own words, a specially crafted flow configuration can "escape the prompt template sandbox" and lead to arbitrary command execution on the AI Gateway.

The CVSS 3.1 vector, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, spells out the exposure: network reachability, low attack complexity, low-privilege authentication required, no user interaction. This is not an unauthenticated internet-facing bug, but in most organizations a large number of developers hold Duo Agent Platform permissions, and a single stolen token or a malicious insider is enough.

What is affected and how to fix it

The AI Gateway is a separately versioned component that sits between your GitLab instance and the AI model providers, so upgrading core GitLab does not fix this. Operators need to update the Gateway image directly. Fixed builds are 19.2.4, 19.3.2, and 19.4.1. Affected versions run from 18.1.6 through versions before 19.2.4, plus 19.3 before 19.3.2 and 19.4 before 19.4.1.

Only organizations running their own AI Gateway need to act. GitLab.com, GitLab Dedicated, and self-managed instances pointing at GitLab-hosted gateways are already patched. GitLab said it did targeted outreach to self-hosted AI Gateway customers before disclosure, and CISA's assessment lists exploitation as "none" as of October 2, meaning no confirmed attacks so far. The flaw was reported through HackerOne by a researcher using the handle invisiblemeerkat.

The second critical gateway flaw this year

This is not the first time the AI Gateway has needed emergency attention. In February, GitLab patched CVE-2026-1868, another CVSS 9.9 issue in the same component, likewise exploitable through a crafted flow definition. Both are classified as template-engine weaknesses under CWE-1336.

The timing is worth noting for a second reason. The same week, GitLab also dealt with CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab Community and Enterprise Editions that CISA added to its actively-exploited list. Security teams running self-hosted GitLab have two separate components to patch, and the fixes do not overlap.

The uncomfortable part for agent infrastructure

The pattern here is bigger than one vendor. The AI Gateway is exactly the kind of component the agent era is producing everywhere: a privileged middle layer that holds JWT signing keys, connects to every AI provider an organization uses, and renders agent configurations as code. When a flaw lets someone escape a sandbox and run commands on that service, they land in a spot with real reach.

The lesson GitLab's advisory carries implicitly is the one to take: treat the gateway as part of your attack surface, inventory where your self-hosted AI components live, and patch the component itself rather than assuming the platform upgrade covered it. Upgrading GitLab CE or EE alone does not remediate CVE-2026-90970.