GitLab has released patches for a severe vulnerability in its self-hosted AI Gateway that could enable a logged-in user with access to Duo Agent Platform to execute commands on the gateway. The flaw, tracked as CVE-2026-90970, was disclosed on October 2 and assigned a critical severity rating with a CVSS score of 9.9 out of 10.
What’s the issue?
The vulnerability lies in the prompt template component of a custom flow, a feature used by organizations running their own AI Gateway to connect their GitLab instance to AI models. A user with Duo Agent access could exploit the flaw by creating a specially crafted flow configuration that breaks out of the “prompt template sandbox,” allowing arbitrary command execution on the gateway. Exact conditions for exploitation remain vague, including what user role is necessary beyond Duo Agent access. These gateways are typically deployed via Docker or Helm and hold critical secrets like JWT signing keys, along with connecting to both GitLab instances and AI model providers.
Who’s impacted & how to fix it
This flaw only affects organizations using a self-managed GitLab AI Gateway—not those on GitLab.com, GitLab Dedicated, or instances that rely on a GitLab-hosted gateway. Affected versions include gateway releases from 18.1.6 up through the 19.1 line, as well as specific minor versions in the 19.2-19.4 series. The vulnerability is resolved starting in versions 19.2.4, 19.3.2, and 19.4.1. Administrators using Docker should stop and remove their existing containers before pulling and running the updated image tags, while those using Helm should update the image tag in their chart configuration.
GitLab has advised all self-hosted gateway users to apply the update immediately. There is currently no workaround for those unable to upgrade at present, and nothing in the advisory indicates whether any systems have already been compromised using this issue. On the same day of disclosure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added to the CVE record that there is no evidence of active exploitation at this time.
This particular issue is part of a broader set of template engine vulnerabilities: earlier in 2026, a related flaw (CVE-2026-1868) was patched that also allowed crafted flow definitions to trigger denial-of-service or remote code execution in the AI Gateway. Both flaws belong to the same class, CWE-1336.
GitLab thanked a security researcher known as invisiblemeerkat for discovering and reporting CVE-2026-90970.
Why this matters, what to watch:
This vulnerability highlights the risks when giving AI tools deep access to underlying infrastructure. As more organizations build internal AI tools or self-host AI services, features like custom flow templates can become attack surfaces if not rigorously sandboxed. The rapid discovery of two major template engine flaws in the AI Gateway within months shows that this area needs stronger design and review.
Enterprises running self-hosted AI systems need to prioritize updates—not just for functionality, but for security. Those relying on self-managed gateways should audit their usage of custom flows, limit access to Duo Agent platforms, rotate JWT keys, and review logs for suspicious activity. Moving forward, AI Gateways should enforce stricter controls on flow templates and privilege separation, or risk becoming the entry point for serious breaches.