← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 3, 2026 · 10:43via Security Affairs

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

Brief

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways.

GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway.

GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19.

  • 4, 19.
  • 2 and 19.
  • 1.

The issue affects the way the AI Gateway handles custom flow prompt templates. According to GitLab, a user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt template sandbox and execute commands on the AI Gateway host.

Read more on Security Affairs→