Vulnerability  ·  2026-10-03

GitLab AI Gateway: prompt-template sandbox escape leads to arbitrary command execution on self-hosted gateway (CVE-2026-90970)

VulnerabilityHigh impactGlobalCVE-2026-90970
GitLab disclosed on 2026-10-02 a critical (CVSS 9.9) vulnerability in the AI Gateway — the service connecting a GitLab instance to AI models. A logged-in Duo Agent Platform user could escape the prompt-template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the gateway. The flaw is a template-engine weakness of the same class (CWE-1336) as the February CVE-2026-1868 gateway flaw. CISA assessed exploitation as 'none' at publication.
The self-hosted AI Gateway sits at the trust boundary between GitLab and both the org's AI model providers and the GitLab instance. It holds JWT signing keys (sensitive credentials) and relays AI requests/responses. Command execution there compromises the AI request path and the gateway's credentials — exactly the kind of MCP/agent-gateway trust boundary that lets an attacker redirect or poison AI traffic enterprise-wide. CVSS 9.9 in widely-deployed GitLab AI infrastructure justifies Tier A.
A logged-in user with Duo Agent Platform access submits a specially crafted custom-flow (agent workflow) configuration whose prompt template escapes the sandbox (CWE-1336 template-injection class), reaching arbitrary command execution on the gateway host.
GitLab AI Gateway 18.1.6-before 19.2.4, 19.3-before 19.3.2, 19.4 before 19.4.1
Upgrade the self-hosted AI Gateway Docker/Helm image to 19.2.4, 19.3.2, or 19.4.1. No workaround listed for unpatchable gateways. GitLab pre-notified self-hosted-gateway customers.
The Hacker News: GitLab Patches Critical 9.9 AI Gateway FlawNVD CVE-2026-90970GitLab work item 628842
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →