Summary
- CVE-2026-90970 carries a CVSS score of 9.9 and affects self-hosted GitLab AI Gateway installations.
- A crafted flow configuration could allow an authenticated Duo Agent Platform user to escape the prompt template sandbox.
- GitLab-hosted gateways have already been fixed, while affected self-hosted installations require an upgrade.
GitLab has released emergency updates for a critical AI Gateway vulnerability that could allow an authenticated user to escape a prompt template sandbox and execute arbitrary commands on self-hosted infrastructure.
GitLab assigned CVE-2026-90970 a CVSS score of 9.9 and is urging customers operating affected self-hosted AI Gateway versions to install corrected releases as soon as possible.
The flaw affects custom flow prompt templates used by GitLab’s Duo Agent Platform. Under specific conditions, an authenticated user with access to the platform could submit a specially crafted flow configuration, escape the intended sandbox and execute commands on the AI Gateway host.
Affected versions begin with GitLab AI Gateway 18.1.6 and include releases before 19.2.4, version 19.3 before 19.3.2 and version 19.4 before 19.4.1. GitLab-hosted gateways have already received the fix, so customers whose deployments use the vendor-hosted service do not need to patch the gateway themselves.
Customers running the gateway in their own environment retain that responsibility, creating an important difference in exposure between hosted and self-hosted deployments even when both form part of the same wider GitLab platform.
Authentication does not substantially reduce the potential impact because the vulnerability crosses the boundary between the privileges granted to a Duo user and control over the infrastructure running the gateway. The CVSS vector reflects low attack complexity, no requirement for user interaction and high potential impact to confidentiality, integrity and availability.
AI gateways increasingly sit between models, enterprise data, tools and internal services, allowing organisations to enforce policy or connect agent workflows with development environments. A vulnerability in that layer can therefore turn an application-level permission into access to infrastructure with a much broader security role.
The mechanism also demonstrates how AI application security remains closely connected with conventional software engineering. Prompt templates are specific to model-driven applications, but the eventual failure is familiar: attacker-controlled input reaches a context where it can influence execution with greater privileges than intended.
Sandboxing is intended to contain that boundary by allowing configurable behaviour without permitting an ordinary user to escape into the host environment. Once an attacker can break that isolation, the security model changes from manipulating an AI workflow to executing commands on the system supporting it.
Self-hosting can appeal to organisations that want tighter control over source code, model interactions, data location or integration with internal services, particularly in regulated environments. Those benefits come with a corresponding requirement to track and deploy security updates across components that a hosted provider would otherwise maintain.
GitLab could remediate its own hosted gateways directly, whereas organisations running the component locally need to identify affected installations and update them. Mixed deployment models can complicate that inventory when some GitLab services remain vendor managed and other AI components have been brought inside the customer’s environment.
The company said it conducted targeted outreach to customers running self-hosted AI Gateways before publishing the advisory. The vulnerability was responsibly disclosed by a researcher using the handle invisiblemeerkat.
GitLab has not reported active exploitation of CVE-2026-90970. The absence of confirmed exploitation does not change the technical severity, but it does define the current evidential boundary: the command execution path has been demonstrated and patched without a publicly identified campaign using it against customer systems.
Versions 19.2.4, 19.3.2 and 19.4.1 contain the correction. Organisations using affected self-hosted installations are being directed to upgrade rather than rely on a separate mitigation.
As agent platforms gain wider access to development and enterprise systems, vulnerabilities of this kind increasingly test whether organisations have extended ordinary asset, patch and privilege management into the infrastructure supporting their AI deployments.





