metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
GitLab
AI Security
AI Gateway
Duo Agent Platform
CVE-2026-90970

GitLab AI Gateway CVE-2026-90970: A 9.9 Sandbox Escape

GitLab patched CVE-2026-90970, a CVSS 9.9 AI Gateway flaw letting Duo Agent Platform users escape a prompt template sandbox. What it teaches about agent security.

Metir AI TeamOctober 5, 20267 min read
GitLab AI Gateway CVE-2026-90970: A 9.9 Sandbox Escape

On October 2, 2026, GitLab disclosed CVE-2026-90970, a critical flaw in the self-hosted GitLab AI Gateway with a CVSS score of 9.9. According to GitLab's advisory, an authenticated user with access to the Duo Agent Platform could escape the prompt template sandbox through a specially crafted flow configuration and run arbitrary commands on the AI Gateway. The fix ships in versions 19.2.4, 19.3.2 and 19.4.1. This piece treats the disclosure as a case study in agent-platform security: why template handling in an AI gateway is a sensitive boundary, why self-hosted AI infrastructure widens the attack surface, and what patching looks like in practice. It stays at the level of the advisory and does not discuss exploitation.

9.9CVSS 3.1 scoreCritical, per GitLab's advisory
3Fixed releases19.2.4, 19.3.2 and 19.4.1
18.1.6First affected versionself-hosted AI Gateway
Oct 2, 2026Disclosure date

What GitLab disclosed

GitLab's advisory is titled "Improper Neutralization issue in custom flow prompt template impacts AI Gateway." The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. In plain terms: it can be reached over the network, needs no special conditions, requires only a low-privilege authenticated account, needs no user interaction, and can have high impact on confidentiality, integrity and availability, with a changed scope.

The affected versions are AI Gateway 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. GitLab credits the researcher "invisiblemeerkat," who reported it through HackerOne. Per GitLab, a fix has already been deployed for GitLab-hosted AI Gateways, so customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway need take no action. The exposure is limited to organizations running their own gateway.

CVE-2026-90970: affected versus fixed

Self-hosted AI Gateway versions per GitLab's advisory. GitLab-hosted gateways were already patched.

Release lineAffectedFixed in
18.1 to 19.2 line18.1.6 through 19.2.319.2.4
19.3 line19.3.0 through 19.3.119.3.2
19.4 line19.4.019.4.1

Any self-hosted gateway on a version in the affected column should move to the fixed release for its line.

Reporting by The Hacker News and BleepingComputer indicates that no public proof of concept or exploitation in the wild was documented at disclosure. Secondary outlets word the affected range slightly differently, so administrators should rely on GitLab's own advisory when checking a specific version.

Template injection in an AI gateway

The advisory's wording places the flaw in how a prompt template is processed for custom flows. The Hacker News classifies it as CWE-1336, improper neutralization of special elements used in a template engine. That class of weakness is old and well understood from web applications: a template engine turns text into output, and if untrusted input can influence the template itself rather than only the data filling it, the engine can end up doing things its designers never intended.

What is new is the setting. In an agent platform, flow configurations and prompt templates are the instructions that shape what an agent does. They are authored by users, shared between teams and loaded by a service that sits close to models, credentials and internal systems. A sandbox around the template engine is meant to keep that authored text from reaching the host. When the sandbox is the only barrier, any gap in it converts a low-privilege user's configuration into code running on the gateway.

“

A prompt template is code that happens to look like prose, and the service that renders it deserves the same scrutiny as any other interpreter.

Analysis

That is why a PR:L (low privileges) rating on a 9.9 score matters. Anyone who can legitimately define a flow is, from the gateway's point of view, a source of semi-trusted input. In an enterprise with many developers on a platform, that population is large.

This is also not the first time the same component has had this class of problem. The Hacker News notes that GitLab fixed CVE-2026-1868, also rated 9.9, in February, describing it as another template engine weakness reachable through a crafted flow definition. GitLab's patch release for that earlier issue lists fixed gateway versions 18.6.2, 18.7.1 and 18.8.1. Two critical findings of one kind in the same service within a year suggest that template handling in agent platforms deserves sustained review, not one-off fixes.

Why self-hosting widens the attack surface

Self-hosting an AI gateway is often a deliberate choice: data residency, regulatory requirements, or a wish to keep prompts and code inside the company network. Those are sound reasons. The trade-off is that the security work moves to the customer in several ways.

Two NASA Glenn Research Center staff members working at racks of rack-mounted computer cluster hardware
Rack-mounted cluster hardware at NASA Glenn Research Center. An illustrative image of self-hosted infrastructure only; it does not depict GitLab or the vulnerability. Photo by NASA, public domain, via Wikimedia Commons.
  • Patch latency is the customer's. GitLab fixed its hosted gateways before the public disclosure. Self-hosted operators only become safe when they upgrade, so the gap between the fix and the deployed fix belongs to them.
  • The gateway is a privileged position. It brokers requests between users, models and tools. Command execution there can reach whatever the host can reach, which is what the changed scope in the CVSS vector reflects.
  • Versioning is a separate track. The gateway has its own release line that can lag the main GitLab instance, so a team that diligently patches GitLab itself can still run an exposed gateway.
  • Container details matter. Reporting on the advisory notes that Docker and Kubernetes deployments should pull updated images and confirm digests and pull policies, because cached images can quietly keep an old version running.

GitLab also said it conducted targeted outreach to self-hosted AI Gateway customers before publishing the release post, which is a reminder to keep security contacts current with vendors.

The same structural pattern appeared in a different product recently. Our analysis of SalesBleed in Salesforce Agentforce covered untrusted input steering a trusted agent. CVE-2026-90970 differs in mechanism, since the input here is configuration rather than a lead form, but the lesson is shared: agent platforms mix text, authority and tools, and each seam needs its own boundary.

Patch and hardening guidance

  1. Inventory your gateways. Identify every self-hosted AI Gateway and its version. Anything from 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, or 19.4.0 is in the affected range.
  2. Upgrade to the fixed release for your line: 19.2.4, 19.3.2 or 19.4.1. GitLab recommends doing so immediately.
  3. Verify the rollout. Confirm the running image digest, not just the tag, and check pull policies so a cached image is not reused.
  4. Reduce who can author flows. Limit Duo Agent Platform flow configuration rights to people who need them, since the flaw requires an authenticated user.
  5. Constrain the host. Run the gateway with least privilege, restrict its outbound network access, and keep secrets it does not need off the machine, so a compromise has less to reach.
  6. Review logs for the disclosure window. The advisory reports no known exploitation, but flow configuration changes made before patching are worth a look.

The takeaway

The disclosure process worked as intended: a researcher reported privately, the vendor patched its hosted service first, then published a fix and contacted self-hosted customers. The open question is structural. As agent platforms let users define flows, templates and tools, those definitions become an input surface that needs the same hardening as any interpreter. For teams that self-host, the practical response is simple and time-sensitive: find the gateway, check the version, and upgrade.

Sources:

  • GitLab AI Gateway patch release advisory for CVE-2026-90970 (GitLab documentation)
  • GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers | The Hacker News
  • GitLab warns of critical RCE vulnerability in AI Gateway service | BleepingComputer
  • Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks | Cyber Security News
  • GitLab AI Gateway Critical Patch Release: 18.6.2, 18.7.1, and 18.8.1 (GitLab documentation)

Image credits

Header and in-body image: "A NASA computer server farm" (NASA Glenn Research Center, image C-2006-1850), by NASA, via Wikimedia Commons, public domain. Illustrative of rack-mounted server hardware only; not related to GitLab or the vulnerability.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational