GITLAB has patched a critical vulnerability in its AI Gateway that could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on the gateway under certain conditions. The flaw stems from a weakness in the prompt template handling within a custom flow, enabling an attacker to escape the template sandbox and run commands on the gateway. GitLab has assigned CVE-2026-90970 to this issue and rated it 9.9 out of 10 on the CVSS scale.
The company has disclosed the advisory on 2 October 2026 and notes that the vulnerability affects self-hosted gateways, with the gateway acting as the bridge between a GitLab instance and external AI models. There is no confirmed exploitation reported in the advisory, though CISA lists “none” for exploitation and notes a public PoC and active exploitation in other fields.
Fixes are available for gateway versions 19.2.4, 19.3.2, and 19.4.1. Users running GitLab[.]com, GitLab Dedicated, or GitLab self-hosted instances that use a GitLab-hosted gateway do not need to take action. However, self-managed customers who operate their own gateway should update immediately; GitLab emphasised this guidance in advance of the advisory. The affected release range for self-hosted gateways runs from 18.1.6 up to 19.1.x, with 19.2.4, 19.3.2, and 19.4.1 providing the fixes.
The flaw involves signing keys for JSON Web Tokens stored on the self-hosted gateway and underscores the importance of securing these credentials as gateways connect to both the GitLab instance and the AI model providers. The advisory credits HackerOne reporter invisiblemeerkat for reporting the flaw.