What happened
GitLab disclosed on 2026-10-02 a critical (CVSS 9.9) vulnerability in the AI Gateway — the service connecting a GitLab instance to AI models. A logged-in Duo Agent Platform user could escape the prompt-template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the gateway. The flaw is a template-engine weakness of the same class (CWE-1336) as the February CVE-2026-1868 gateway flaw. CISA assessed exploitation as 'none' at publication.
Why it matters
The self-hosted AI Gateway sits at the trust boundary between GitLab and both the org's AI model providers and the GitLab instance. It holds JWT signing keys (sensitive credentials) and relays AI requests/responses. Command execution there compromises the AI request path and the gateway's credentials — exactly the kind of MCP/agent-gateway trust boundary that lets an attacker redirect or poison AI traffic enterprise-wide. CVSS 9.9 in widely-deployed GitLab AI infrastructure justifies Tier A.
Attack vector
A logged-in user with Duo Agent Platform access submits a specially crafted custom-flow (agent workflow) configuration whose prompt template escapes the sandbox (CWE-1336 template-injection class), reaching arbitrary command execution on the gateway host.
Affected systems
GitLab AI Gateway 18.1.6-before 19.2.4, 19.3-before 19.3.2, 19.4 before 19.4.1
Mitigation
Upgrade the self-hosted AI Gateway Docker/Helm image to 19.2.4, 19.3.2, or 19.4.1. No workaround listed for unpatchable gateways. GitLab pre-notified self-hosted-gateway customers.