Image: thaicert.or.th · rights & removal
GitLab Patches Critical AI Gateway Vulnerability That Could Allow Command Execution on Self
Reporting by Thailand ThaiCERT AdvisoriesRead the original at thaicert.or.th
Executive Summary
Facts Only
* Vulnerability ID: CVE-2026-90970, CVSS score of 9.9.
* Vulnerability affects GitLab AI Gateway.
* The vulnerability allows an authenticated user with Duo Agent Platform access to execute commands on the AI Gateway.
* The issue involves the handling of Custom Flow Prompt Templates in AI Gateway.
* Exploitation involves submitting a specially crafted Flow Configuration to escape the Prompt Template Sandbox and execute host commands.
* Fixes were released in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.
* The vulnerability was disclosed on October 2, 2026, via HackerOne by researcher invisiblemeerkat.
* AI Gateway acts as an intermediary between GitLab Duo and AI models.
* Patches are required for self-hosted deployments running affected versions: 18.1.6 through 19.2.3 (to 19.2.4); 19.3.0 through 19.3.1 (to 19.3.2); and 19.4.0 (to 19.4.1).
* Customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-managed Gateway do not need action.
Full Take
From the original · Thailand ThaiCERT Advisories
545/69 Monday, October 5, 2026 GitLab has released patches for a Critical vulnerability in GitLab AI Gateway, tracked as CVE-2026-90970 with a CVSS score of 9.9. The vulnerability could allow an authenticated user with access to the Duo Agent Platform to execute commands on the AI Gateway.Read the full story at thaicert.or.th
Sentinel — Human
The text appears to be a factual report derived directly from a technical disclosure, exhibiting high internal consistency typical of professional security journalism.
