GitLab rushes a fix for a sandbox escape in its AI Gateway

A signed-in Duo user could break out of a prompt template sandbox and run commands on self-hosted AI Gateway hosts, GitLab warned.

CSBadmin
2 Min Read

GitLab has released fixes for a critical flaw in its AI Gateway, the component that routes requests between a GitLab instance and the AI models behind it.

Tracked as CVE-2026-90970, the bug carries a severity score of 9.9. GitLab says a signed-in user who can reach the Duo Agent Platform could craft a flow configuration that slips past the prompt template sandbox. The break-out lets an attacker run arbitrary commands on the gateway server.

Only organizations that host their own gateway have to move. GitLab has already cleaned up the gateways it operates, so customers on GitLab.com, GitLab Dedicated, or a self-managed instance wired to a GitLab-hosted gateway can stand down. Self-managed users who keep the gateway inside their own environment were contacted directly and told to update immediately.

Patched AI Gateway releases are 19.2.4, 19.3.2 and 19.4.1. Nothing below 19.2.4 has a fix, leaving the 18.1.6 through 19.1 line exposed. Docker and Helm deployments need their image tag bumped and the container restarted.

The severity is high because a gateway an organization runs itself stores the JSON Web Token signing and validation keys that GitLab regards as sensitive credentials, and it bridges the internal GitLab instance and the outside AI providers.

GitLab credited HackerOne researcher invisiblemeerkat. The advisory offers no workaround for administrators who cannot patch yet, and it stays silent on whether anyone has abused the bug in the wild. CISA’s assessment records exploitation as “none.” It is the second template-engine flaw of this class in the gateway this year, after CVE-2026-1868, also rated 9.9.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.