GITLAB has patched a critical flaw in its AI Gateway (CVE-2026-90970) that could allow an authenticated Duo Agent Platform user to execute arbitrary commands on self-hosted gateways. GitLab AI Gateway versions 18.1.6 up to, but not including, 19.2.4; 19.3 before 19.3.2; and 19.4 before 19.4.1 are affected. The fix was released in versions 19.2.4, 19.3.2 and 19.4.1.
The vulnerability is scored at CVSS 3.1 with a 9.9 (Critical) rating, and it concerns improper neutralisation of elements used in a template engine within the Gateway. At present, there are no confirmed exploitations in the wild, and no PoC publicised, with GitLab noting that hosted gateways are already protected.
The weakness lies in custom flow prompt templates, where an authenticated user could “escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.” The issue is categorised as server-side template injection (CWE-1336) by TheHackerWire, with the researcher invisiblemeerkat credited. Only self-hosted deployments require action; GitLab[.]com, GitLab Dedicated, and self-managed instances using a GitLab-hosted AI Gateway are protected.
GitLab urges admins to upgrade affected self-hosted gateways to 19.2.4, 19.3.2 or 19.4.1 as a matter of urgency and to review Duo Agent Platform access to limit exposure until upgrades are complete.