GitLab Patches 9.9-Rated AI Gateway Flaw Allowing Command Execution

GitLab patched a critical 9.9-rated AI Gateway flaw that could let authenticated users escape a sandbox and execute commands on self-hosted systems.

Oct 5, 2026
2 minute read
GitLab homepage.

GitLab urges immediate patching of critical AI gateway RCE flaw. Image: Pankaj Patel/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A critical GitLab AI Gateway vulnerability could allow an authenticated user to escape a prompt-template sandbox and execute commands on vulnerable self-hosted systems.

GitLab disclosed CVE-2026-90970 on Friday and rated it 9.9 out of 10 under the CVSS scoring system. The vulnerability affects self-hosted AI Gateway deployments and stems from improper neutralization in custom flow prompt templates.

Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway, GitLab said.

The company released versions 19.2.4, 19.3.2 and 19.4.1 to fix the issue and said it had already contacted customers operating self-hosted gateways before publishing the advisory.

The vulnerability affects AI Gateway versions from 18.1.6 through releases before 19.2.4, as well as the 19.3 branch before 19.3.2 and the 19.4 branch before 19.4.1.

Cloud users are already protected

Not every GitLab customer needs to do anything. GitLab said it has already deployed the fix to its hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, or a GitLab Self-Managed instance connected to a GitLab-hosted gateway are therefore protected.

The urgent work falls on organizations running their own AI Gateway. Because the gateway is a separate component, administrators need to check its deployed version rather than assume that updating the main GitLab installation is enough.

Why the gateway is the real concern

The vulnerability is more serious than a flaw that merely manipulates an AI response. A successful sandbox escape can reach command execution on the system running the gateway.

That matters because the AI Gateway sits between GitLab’s AI features and the underlying models, processing requests and connecting the platform to AI infrastructure. Self-hosted deployments can also contain sensitive authentication material, meaning a compromised gateway could become a useful foothold for further attacks.

GitLab has not said that CVE-2026-90970 is being exploited in the wild. It also has not published a proof of concept or detailed exploitation instructions.

Advertisement

What administrators should do

Organizations running an affected self-hosted gateway should upgrade to the appropriate fixed release immediately: 19.2.4, 19.3.2, or 19.4.1.

Administrators should verify the AI Gateway version separately from the main GitLab installation, because patching GitLab itself does not necessarily update a self-hosted gateway.

Security teams should also review who has Duo Agent Platform access and examine recent custom-flow configurations for unexpected changes. GitLab has not listed a workaround for systems that cannot be upgraded.

There is currently no indication that CVE-2026-90970 is being exploited in the wild. Still, its 9.9 CVSS score and ability to reach command execution make rapid patching the safest response.

Other news: Cybersecurity Awareness Month is putting the focus on four practical habits for 2026: patching faster, using MFA without overrelying on it, questioning legitimate-looking requests, and assuming some personal data is already exposed.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.