GitLab has rushed out fixes for a critical vulnerability in its AI Gateway, the component that routes requests between a GitLab instance and the AI models behind it. Tracked as CVE-2026-90970 and disclosed October 2, the bug carries a CVSS score of 9.9 — and it lands on infrastructure most teams never think of as an attack surface.
According to GitLab's advisory, a signed-in user who can reach the Duo Agent Platform could craft a flow configuration that escapes the prompt-template sandbox. From there, an attacker can run arbitrary commands on the gateway server itself. The flaw is classified under CWE-1336, the template-engine weakness family: the component executes user-authored instructions, and crafted input can cross the boundary into real execution.
The exposure is narrower than a typical remote hole — it requires an authenticated account with Duo Agent Platform access — but the blast radius of a compromised gateway is what makes the severity justified. Self-hosted AI Gateway deployments store the JSON Web Token signing and validation keys that GitLab classifies as sensitive credentials, and they bridge an organization's internal GitLab instance to outside AI providers. Command execution there means a foothold between your source code and every model provider you use.
Who needs to act is a short list: only organizations that host their own gateway. GitLab has already cleaned up the gateways it operates, so customers on GitLab.com, GitLab Dedicated, or self-managed instances wired to a GitLab-hosted gateway can stand down. Self-hosted gateway customers were contacted directly before the advisory went public and told to update immediately. Patched releases are 19.2.4, 19.3.2 and 19.4.1; every version from 18.1.6 up to those builds is exposed, and there is no listed fixed build for lines older than 19.2. Docker and Helm deployments need their image tag bumped and the container restarted — GitLab warns that cached images can silently keep the old code, and recommends deploying by digest.
The advisory offers no workaround for teams that cannot patch yet, and it stays silent on abuse in the wild; CISA's assessment currently records exploitation as "none." The bug was reported through HackerOne by a researcher using the handle invisiblemeerkat.
What should trouble security teams is the pattern. This is the second CVSS 9.9 flaw in the same gateway component this year — CVE-2026-1868, patched in February, was exploitable through essentially the same mechanism: a crafted flow definition. Both are template-engine weaknesses. In other words, the part of GitLab that executes AI workflow instructions has now produced two critical escapes in eight months, and both lived in the same design decision: treating user-authored templates as configuration rather than as code.
The practical takeaway goes beyond GitLab. Any service that executes user- or agent-authored prompts, flows, or templates deserves the same access review as one that executes user-authored code: list who holds AI platform access, restrict who can define custom flows, and treat the AI gateway as production infrastructure with secrets inside it — because that is exactly what it is.
Comments (0)
Log in to join the discussion
Log InNo comments yet