securityaffairs.com 3 Oct 2026, 10:43 UTC

GitLab AI Gateway Flaw Lets Users Run Commands on Hosts

GitLab AI Gateway Flaw Lets Users Run Commands on Hosts
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

GITLAB has patched a critical vulnerability in its AI Gateway, CVE-2026-90970, rated 9.9 on the CVSS scale. The flaw could allow an authenticated user with access to the Duo Agent Platform to escape the prompt sandbox and execute arbitrary commands on the AI Gateway host. GitLab disclosed the issue on 2 October 2026 and released fixes in AI Gateway versions 19.2.4, 19.3.2 and 19.4.1.

The advisory notes that exploitation would require specific conditions involving a crafted flow configuration, and does not indicate that the vulnerability has been observed in the wild.

The problem lies in how the AI Gateway handles custom flow prompt templates, with the gateway acting as the intermediary between GitLab Duo and underlying AI models. Self-hosted deployments are affected, including installations where the gateway and AI models reside within an organisation’s infrastructure; GitLab states that the issue could grant an attacker foothold into environments handling AI requests and authentication keys.

Affected releases are 18.1.6 through 19.2.3 (fixed in 19.2.4); 19.3.0 through 19.3.1 (fixed in 19.3.2); and 19.4.0 (fixed in 19.4.1). The advisory confirms the issue did not pertain to unauthenticated access, and no proof-of-concept or exploitation details were published. Credit for reporting is given to the HackerOne researcher invisblemeerkat. GitLab notes that customers using GitLab[.]com, GitLab Dedicated, or a GitLab self-managed gateway connected to a GitLab-hosted gateway do not need to take action.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline