# GitLab Patches Critical AI Gateway Flaw Allowing Arbitrary Command Execution


GitLab has fixed a critical vulnerability in its AI Gateway that could allow an authenticated user with Duo Agent Platform access to escape a prompt template sandbox and execute arbitrary commands on the gateway.


Tracked as **CVE-2026-90970**, the vulnerability has a **CVSS score of 9.9 out of 10**. GitLab disclosed the flaw on October 2, 2026, and released fixes in AI Gateway versions **19.2.4, 19.3.2, and 19.4.1**.


## Who Is Affected?


The vulnerability primarily affects organizations running a **self-hosted GitLab AI Gateway**.


GitLab operates its own AI Gateway infrastructure for GitLab.com, GitLab Self-Managed, and GitLab Dedicated. Customers using a GitLab-hosted gateway have already been protected and do not need to take action.


Organizations that deploy their own AI Gateway should update immediately.


The AI Gateway is a standalone service that provides access to AI-native GitLab Duo features. Self-hosted deployments can be operated through GitLab Duo Self-Hosted.


## CVE-2026-90970 Details


The flaw is related to improper handling of special elements in a template engine and is classified under **CWE-1336**.


According to GitLab, an authenticated user with Duo Agent Platform access could exploit a specially crafted flow configuration to escape the prompt template sandbox.


A successful escape could result in **arbitrary command execution on the AI Gateway**.


The publicly disclosed information does not specify all conditions required for exploitation or identify a more specific user role beyond Duo Agent Platform access.


## Affected and Fixed Versions


| AI Gateway Version | First Fixed Version |

|---|---|

| 18.1.6 or later, before 19.2.4 | **19.2.4** |

| 19.3 before 19.3.2 | **19.3.2** |

| 19.4 before 19.4.1 | **19.4.1** |


The affected versions are separate from the main GitLab application version because the AI Gateway is deployed as its own Docker image or Helm deployment.


Administrators should update the AI Gateway to an appropriate fixed release.


## Self-Hosted Gateway Administrators Should Update


For Docker deployments, administrators need to replace the existing gateway container with a fixed image tag.


Helm deployments require updating the gateway image tag in the Helm configuration.


GitLab does not list a workaround for installations that cannot immediately upgrade.


The advisory also does not provide a specific method for determining whether a vulnerable gateway was previously compromised.


## Why the AI Gateway Is Sensitive


A self-hosted AI Gateway can handle sensitive credentials and communicate with the GitLab environment and configured AI model providers.


GitLab's documentation states that gateway JWT signing keys must be treated as sensitive credentials.


As a result, arbitrary command execution on a gateway could expose credentials, configuration information, or other data accessible from the gateway environment, depending on how the organization has deployed and configured the service.


## No Exploitation Confirmed


GitLab's advisory does not state that CVE-2026-90970 has been exploited in attacks.


The October 2 assessment associated with the CVE lists exploitation as **none** at the time of assessment.


There is also no publicly documented exploitation campaign associated with the vulnerability in the available advisory information.


## Previous AI Gateway Vulnerability


GitLab previously fixed another critical AI Gateway vulnerability, **CVE-2026-1868**, which also received a **CVSS score of 9.9**.


That vulnerability involved insecure template expansion through crafted Duo Agent Platform Flow definitions and could result in denial of service or code execution on the gateway.


Both vulnerabilities involve template processing weaknesses and are classified under **CWE-1336**.


## Recommended Actions


Organizations running a self-hosted GitLab AI Gateway should:


- Check the currently deployed AI Gateway version.

- Upgrade to **19.2.4, 19.3.2, or 19.4.1**, as applicable.

- Review recent Duo Agent Platform flow configurations for unexpected changes.

- Review gateway logs for suspicious command execution or configuration activity.

- Protect JWT signing keys and other gateway credentials.

- Investigate suspicious activity that occurred before the upgrade.

- Follow GitLab's official AI Gateway upgrade instructions.