Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week

GitLab Patches a CVSS 9.9 Sandbox Escape in Its Self-Hosted AI Gateway — the Second Critical Flaw in the Component This Year

GitLab Patches a CVSS 9.9 Sandbox Escape in Its Self-Hosted AI Gateway — the Second Critical Flaw in the Component This Year

GitLab disclosed CVE-2026-90970 on October 2, a CVSS 9.9 flaw letting an authenticated Duo Agent Platform user escape the AI Gateway's prompt-template sandbox and run arbitrary commands on self-hosted gateways holding JWT signing keys. Fixed builds: 19.2.4, 19.3.2 and 19.4.1. GitLab-hosted gateways are already patched.

GitLab has rushed out fixes for a critical vulnerability in its AI Gateway, the component that routes requests between a GitLab instance and the AI models behind it. Tracked as CVE-2026-90970 and disclosed October 2, the bug carries a CVSS score of 9.9 — and it lands on infrastructure most teams never think of as an attack surface.

According to GitLab's advisory, a signed-in user who can reach the Duo Agent Platform could craft a flow configuration that escapes the prompt-template sandbox. From there, an attacker can run arbitrary commands on the gateway server itself. The flaw is classified under CWE-1336, the template-engine weakness family: the component executes user-authored instructions, and crafted input can cross the boundary into real execution.

The exposure is narrower than a typical remote hole — it requires an authenticated account with Duo Agent Platform access — but the blast radius of a compromised gateway is what makes the severity justified. Self-hosted AI Gateway deployments store the JSON Web Token signing and validation keys that GitLab classifies as sensitive credentials, and they bridge an organization's internal GitLab instance to outside AI providers. Command execution there means a foothold between your source code and every model provider you use.

Who needs to act is a short list: only organizations that host their own gateway. GitLab has already cleaned up the gateways it operates, so customers on GitLab.com, GitLab Dedicated, or self-managed instances wired to a GitLab-hosted gateway can stand down. Self-hosted gateway customers were contacted directly before the advisory went public and told to update immediately. Patched releases are 19.2.4, 19.3.2 and 19.4.1; every version from 18.1.6 up to those builds is exposed, and there is no listed fixed build for lines older than 19.2. Docker and Helm deployments need their image tag bumped and the container restarted — GitLab warns that cached images can silently keep the old code, and recommends deploying by digest.

The advisory offers no workaround for teams that cannot patch yet, and it stays silent on abuse in the wild; CISA's assessment currently records exploitation as "none." The bug was reported through HackerOne by a researcher using the handle invisiblemeerkat.

What should trouble security teams is the pattern. This is the second CVSS 9.9 flaw in the same gateway component this year — CVE-2026-1868, patched in February, was exploitable through essentially the same mechanism: a crafted flow definition. Both are template-engine weaknesses. In other words, the part of GitLab that executes AI workflow instructions has now produced two critical escapes in eight months, and both lived in the same design decision: treating user-authored templates as configuration rather than as code.

The practical takeaway goes beyond GitLab. Any service that executes user- or agent-authored prompts, flows, or templates deserves the same access review as one that executes user-authored code: list who holds AI platform access, restrict who can define custom flows, and treat the AI gateway as production infrastructure with secrets inside it — because that is exactly what it is.

Comments (0)

Log in to join the discussion

Log In

No comments yet