Critical Vulnerability in GitLab AI Gateway Allows Command Execution
GitLab has released critical patches for its Self-Hosted AI Gateway to address CVE-2026-90970, a vulnerability allowing authenticated users to execute arbitrary commands.

GitLab has issued urgent security patches for its Self-Hosted AI Gateway, addressing a critical vulnerability identified as CVE-2026-90970. The patches are available in versions 19.2.4, 19.3.2, and 19.4.1. This vulnerability carries a severe CVSS score of 9.9, indicating a high risk of exploitation.
The flaw resides within the prompt template sandbox mechanism of the AI Gateway. An authenticated user with Duo Agent Platform access can exploit this by crafting a malicious flow configuration. This crafted input allows them to escape the sandbox environment, ultimately leading to the execution of arbitrary commands on the AI Gateway itself. This capability poses a significant threat, potentially allowing attackers to compromise the integrity and confidentiality of the system.
GitLab has identified the impacted versions as all versions from 18.1.6 prior to 19.2.4, versions 19.3 prior to 19.3.2, and versions 19.4 prior to 19.4.1. The company has proactively reached out to affected Self-Hosted AI Gateway customers to inform them of the critical nature of this vulnerability and to provide guidance on updating.
For customers utilizing GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances that employ a GitLab-hosted AI Gateway, no immediate action is required. These environments are considered protected as the fix has already been deployed. The primary focus for remediation is on self-managed installations where customers are responsible for managing their AI Gateway instances.
GitLab strongly urges all administrators of Self-Hosted AI Gateway installations running any of the affected versions to upgrade to one of the patched versions as soon as possible. Detailed instructions for updating the GitLab Self-Hosted AI Gateway can be found in the official GitLab Self-Hosted AI Gateway install documentation.
This vulnerability was responsibly disclosed by a security researcher known as 'invisiblemeerkat'. The detailed CVSS score breakdown (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) highlights the network-exploitable nature, low attack complexity, the need for low privileges, no user interaction, a complex attack scope, and high impact on confidentiality, integrity, and availability.
To stay informed about future security releases, customers can subscribe to GitLab's patch release RSS feed or their general release RSS feed. This incident underscores the importance of timely patching, especially for critical components like AI gateways that handle sensitive data and processing.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an assessment to CVE-2026-90970, indicating that exploitation of the GitLab AI Gateway vulnerability is currently listed as 'none.' This contrasts with CISA's other assessment categories, which include public proof-of-concept availability and active exploitation, suggesting no known in-the-wild attacks have been detected for this specific flaw.