Skip to content

Image: thaicert.or.th · rights & removal

Executive Summary

GitLab released patches for a critical vulnerability, CVE-2026-90970, affecting the GitLab AI Gateway. The vulnerability could allow an authenticated user with access to the Duo Agent Platform to execute commands on the AI Gateway. The flaw relates to the handling of Custom Flow Prompt Templates within the AI Gateway. A user with access to the Duo Agent Platform might be able to submit a specially crafted Flow Configuration to escape the Prompt Template Sandbox and execute commands on the host. GitLab has provided fixes in versions 19.2.4, 19.3.2, and 19.4.1. Customers using GitLab.com, GitLab Dedicated, or Self-Managed instances connected to a GitLab-managed Gateway are exempt from immediate action. However, organizations running self-hosted GitLab AI Gateways must update immediately. Specific affected versions requiring updates include 18.1.6 through 19.2.3 (upgrade to 19.2.4), 19.3.0 through 19.3.1 (upgrade to 19.3.2), and 19.4.0 (upgrade to 19.4.1). Although GitLab has not disclosed exploitation details, prompt updates are advised because the AI Gateway handles sensitive information like JWT signing keys via environment variables.

Facts Only

* Vulnerability ID: CVE-2026-90970, CVSS score of 9.9.
* Vulnerability affects GitLab AI Gateway.
* The vulnerability allows an authenticated user with Duo Agent Platform access to execute commands on the AI Gateway.
* The issue involves the handling of Custom Flow Prompt Templates in AI Gateway.
* Exploitation involves submitting a specially crafted Flow Configuration to escape the Prompt Template Sandbox and execute host commands.
* Fixes were released in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.
* The vulnerability was disclosed on October 2, 2026, via HackerOne by researcher invisiblemeerkat.
* AI Gateway acts as an intermediary between GitLab Duo and AI models.
* Patches are required for self-hosted deployments running affected versions: 18.1.6 through 19.2.3 (to 19.2.4); 19.3.0 through 19.3.1 (to 19.3.2); and 19.4.0 (to 19.4.1).
* Customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-managed Gateway do not need action.

Full Take

The narrative emphasizes the inherent tension between platform trust and execution control. The vulnerability structure points toward a critical failure in separating context management (Prompt Templates) from execution boundaries (the host system). The fact that access to a seemingly related platform, the Duo Agent Platform, is sufficient for exploitation suggests a systemic weakness where privilege escalation chains are poorly mapped across interconnected services. The lack of public exploitation details shifts the focus onto defensive urgency based on potential exposure rather than confirmed malicious activity, which can induce a specific type of operational panic. Furthermore, the necessity of patching self-hosted deployments highlights an asymmetric risk: managed cloud infrastructure is seemingly protected by default, while self-managed environments assume greater immediate liability for securing underlying infrastructure where secrets are processed. The pattern suggests that complexity in interconnected systems (AI gateway, agent platform, prompt handling) creates novel attack surfaces, and resilience depends on correctly segmenting access controls across the entire data pipeline, not just fixing a single code flaw. What structures govern the trust relationship between the Agent Platform, the Gateway, and the host environment? How do organizations manage the implicit dependencies created when leveraging interconnected AI services?

From the original · Thailand ThaiCERT Advisories

545/69 Monday, October 5, 2026 GitLab has released patches for a Critical vulnerability in GitLab AI Gateway, tracked as CVE-2026-90970 with a CVSS score of 9.9. The vulnerability could allow an authenticated user with access to the Duo Agent Platform to execute commands on the AI Gateway.
Read the full story at thaicert.or.th

Sentinel — Human

Confidence

The text appears to be a factual report derived directly from a technical disclosure, exhibiting high internal consistency typical of professional security journalism.

Signals Detected
low severity: Moderate sentence length variance, standard reporting cadence.
low severity: Clear and focused structure; presents technical details followed by remediation steps effectively.
low severity: Direct attribution to GitLab and specific version numbers; citation of a specific external source.
low severity: Highly specific, verifiable technical details (CVE number, versions, dates) typical of security reporting.
Human Indicators
The text follows the structure of a formal security advisory, citing specific CVEs, patch versions, and external reports.
GitLab Patches Critical AI Gateway Vulnerability That Could Allow Command Execution on Self | Huntaegis