Self-Hosted GitLab AI Gateway Users Need to Patch
Matthew Leo · Published October 4, 2026 · Guides
Organizations running their own GitLab AI Gateway need to patch CVE-2026-90970. GitLab rates the vulnerability 9.9 out of 10 because an authenticated user with access to the Duo Agent Platform could escape a prompt-template sandbox and execute commands on the gateway.
This is not a warning for every GitLab customer. GitLab says its hosted AI Gateway has already been updated. The action is for teams that operate a self-hosted AI Gateway through GitLab Duo Self-Hosted.
Which versions are affected
GitLab's security release lists these affected ranges:
- AI Gateway 18.1.6 through versions before 19.2.4
- AI Gateway 19.3 through versions before 19.3.2
- AI Gateway 19.4 through versions before 19.4.1
The fixed releases are 19.2.4, 19.3.2 and 19.4.1. A later supported AI Gateway release should include the fix. Administrators should verify the version of the gateway deployment itself rather than assuming the main GitLab application version answers the question.
What the flaw allows
The problem is in custom flow prompt templates. A crafted flow configuration could bypass the template sandbox and reach arbitrary command execution on the AI Gateway.
The attacker still needs an authenticated account with Duo Agent Platform access. That requirement lowers exposure compared with an unauthenticated internet attack, but it does not make the issue minor. Compromised credentials, an overly broad internal account or a malicious user could provide the starting access.
BleepingComputer independently reported that GitLab's cloud-hosted gateway was already protected when the advisory became public. GitLab has not said the flaw is being exploited in the wild.
What administrators should do
- Confirm whether the gateway is self-hosted. Document the deployment owner, environment and installed AI Gateway version.
- Move to a fixed release. Follow the upgrade method used for that deployment and preserve the previous configuration for rollback.
- Review custom flows. Look for unfamiliar flow definitions, unexpected changes and templates created or modified by accounts with Duo access.
- Check gateway and host logs. Review activity before and after suspicious flow changes, including child processes, unusual outbound connections and access to secrets.
- Limit access after patching. Remove Duo Agent Platform access from accounts that do not need to create or run flows.
If the review finds suspicious command execution, treat the host as potentially compromised. Preserve evidence, rotate credentials the gateway could reach and follow the organization's incident-response process. Installing the patch closes the known path; it does not undo activity that may already have occurred.
Do not confuse this with ordinary prompt injection
Prompt injection usually manipulates an agent's instructions or output. CVE-2026-90970 crosses a different boundary: GitLab says a flow configuration could escape the sandbox and execute commands on the service. That is why the issue received a near-maximum severity score.
Mapletechie recently covered two compromised GitHub Actions and the need to check what automation credentials could reach. The same response principle applies here. Patch the component, then investigate the permissions and secrets available to it.
Sources
Tags: GitLab, CVE-2026-90970, AI Gateway, GitLab Duo, cybersecurity