GitLab AI Gateway flaw CVE-2026-90970 enables RCE
GitLab is urging customers who run their own AI Gateway to update now. The company fixed a critical vulnerability that could let an authenticated attacker execute arbitrary commands on the service.
The flaw is tracked as CVE-2026-90970. According to GitLab, an attacker needs only basic privileges and access to the Duo Agent Platform to exploit it on an unpatched instance.
What the AI Gateway does
AI Gateway is the component that connects GitLab users to the AI-native features of GitLab Duo, the company's set of AI-assisted development tools. GitLab runs its own cloud-based AI Gateway, which serves GitLab.com, GitLab Self-Managed and GitLab Dedicated customers.
Organizations can also deploy their own AI Gateway on GitLab Self-Managed through GitLab Duo Self-Hosted. This option lets companies keep AI processing on their own infrastructure, and it is the setup affected by the new vulnerability.
Escaping the prompt template sandbox
GitLab describes CVE-2026-90970 as an improper neutralization weakness. In practice, a user could break out of the sandbox that is meant to contain prompt templates.
"GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway," the company said in an advisory published on Friday.
GitLab did not share further technical details. The attack path is clear enough from the advisory: a crafted flow configuration takes the attacker from ordinary agent platform access to command execution on the gateway itself.
Patched versions and who needs to act
The fix ships in versions 19.2.4, 19.3.2 and 19.4.1 for Self-Hosted AI Gateway deployments. Customers who rely on the GitLab-hosted AI Gateway are already protected and do not need to do anything.
"These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately," GitLab said.
The company added that it contacted Self-Hosted AI Gateway customers directly before the public release. "We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance," it noted.
A busy few weeks for GitLab security
This is not the only serious GitLab issue in recent weeks. Last month the company patched CVE-2026-85706, a maximum severity path traversal flaw in GitLab Community Edition (CE) and Enterprise Edition (EE). It allows unauthenticated attackers to read sensitive data from vulnerable servers, including credentials and other secrets.
A day after that patch, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its catalog of actively exploited vulnerabilities. Under Binding Operational Directive (BOD) 26-04, a mandatory instruction for U.S. federal civilian agencies, those agencies got three days to secure their systems.
CISA has flagged five GitLab vulnerabilities as exploited in the wild since November 2021. One of them was used by ransomware gangs. Separately, we recently reported on how exposed GitLab email addresses could let attackers push code.
There is no indication in GitLab's advisory that CVE-2026-90970 has been exploited. Given the platform's reach, it is still likely to draw attention. GitLab's DevSecOps platform has more than 30 million registered users and is used by more than half of Fortune 100 companies, among them Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus and UBS.
Our take
The vulnerability shows that the plumbing behind AI features is now part of the attack surface. The AI Gateway sits between users, agent workflows and the models they call. A sandbox escape there turns access to an AI feature into command execution on infrastructure. That is a familiar pattern in AI agent tooling, and similar issues have surfaced in enterprise agent platforms in recent weeks.
The self-hosted angle matters too. Companies often choose GitLab Duo Self-Hosted to keep code and prompts in-house. This case suggests that this approach also moves the patching burden onto their own teams. Cloud users were covered automatically, while self-managed customers have to act.
Exploitation requires authentication, which narrows the risk somewhat. Insiders, compromised accounts or overly broad Duo Agent Platform permissions could still be enough. Administrators should check who holds that access.
It is worth watching whether CVE-2026-90970 follows CVE-2026-85706 onto CISA's exploited list. With exploitation timelines shrinking, patching soon is the safer choice.
