- GitLab disclosed a critical vulnerability, CVE-2026-90970, in its AI Gateway with a CVSS score of 9.9.
- The flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on the gateway.
- Fixes are available in gateway versions 19.2.4, 19.3.2, and 19.4.1; GitLab strongly recommends self-hosted gateway users update immediately.
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory on October 2. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act.
The flaw is tracked as CVE-2026-90970 and was rated critical with a CVSS score of 9.9 out of 10. GitLab runs AI Gateways for its customers and has already fixed them, meaning customers on GitLab.com, GitLab Dedicated, and self-managed instances using a GitLab-hosted gateway do not need to act.
Self-managed customers who host their own gateway are advised to update immediately. The advisory does not say whether the flaw has been used in attacks, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed exploitation as “none.”
The vulnerability is in the prompt template of a custom flow on the Duo Agent Platform. A logged-in user with access could “escape the prompt template sandbox via a specially crafted flow configuration,” leading to arbitrary command execution on the gateway.
GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw. In February, GitLab fixed another gateway flaw, CVE-2026-1868, which also had a 9.9 rating and was a template engine weakness of the same class, CWE-1336.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
