Threat
GitLab AI Gateway Flaw CVE-2026-90970: CVSS 9.9 [2026]
First reported tech-insider.org
Page published · Page updated
Earliest dated coverage: 7 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 7 Oct 2026
Coverage timeline
Single-source advisory — one report is available.
Why it matters
CVE-2026-90970 shows how a prompt-template sandbox escape in an autonomous coding-agent platform can turn a low-privilege developer account into full command execution on the AI Gateway host, exactly the kind of agentic-tooling weakness defenders in regulated, self-hosted environments must patch.
CVE-2026-90970 is a critical (CVSS 9.9) flaw in GitLab's self-managed AI Gateway, part of the Duo Agent Platform, that lets an authenticated user with Duo Agent Platform access escape the prompt-template sandbox via a crafted flow configuration and achieve arbitrary command execution on the gateway host. GitLab shipped emergency patches on October 2, 2026; GitLab.com's hosted service is unaffected, but self-managed deployments running the AI Gateway were exposed.
Summary
GitLab disclosed CVE-2026-90970 on October 2, 2026, a CVSS 9.9 critical flaw in its self-managed AI Gateway that allows an authenticated user with Duo Agent Platform access to escape the prompt-template sandbox through a specially crafted flow configuration and execute arbitrary commands on the AI Gateway host.[0][1]
Patches were released the same day as disclosure, and the flaw does not affect GitLab.com-hosted AI Gateway or GitLab Dedicated; exposure is limited to organizations running a self-hosted AI Gateway. As of the days immediately following disclosure, there was no reported in-the-wild exploitation and no published proof-of-concept.[0]
The vulnerability is characterized as a sandbox escape rather than ordinary prompt injection, meaning an architectural failure of the isolation boundary between user-supplied flow configuration and host execution, which required three separate point releases across three branches to fix.[0]
Attack chain
- Precondition / Access: Attacker holds an existing authenticated account with Duo Agent Platform permissions, a bar described as low in enterprises that grant such access broadly to engineering staff, potentially obtained via phished credentials or insider access.[0]
- Sandbox escape: The attacker submits a specially crafted flow configuration that escapes the prompt-template sandbox meant to wall off user-supplied configuration from the execution environment.[0][1]
- Command execution: The escape results in arbitrary command execution on the AI Gateway host; with a 'changed' CVSS scope, the attacker can affect resources beyond the initially accessed component.[0][1]
Disclosure timeline
| Date | Event |
|---|---|
| 2026-10-02 | GitLab disclosed CVE-2026-90970 and shipped fixed releases (19.2.4, 19.3.2, 19.4.1) the same day.[0] |
| 2026-10-03 | Security outlets reported no evidence of in-the-wild exploitation and no published proof-of-concept exploit code.[0] |
How it works
Duo Agent Platform lets users build custom 'flows'—automated sequences combining prompts, tool calls, and logic—which pass through a prompt-template system intended to keep user-supplied configuration isolated from the underlying execution environment. CVE-2026-90970 breaks that isolation: a specially crafted flow configuration escapes the prompt-template sandbox and reaches the host operating system, enabling arbitrary command execution.[0][1]
This is categorized as a sandbox escape rather than prompt injection; the failure is architectural (the isolation boundary itself) rather than behavioral, which is why remediation required rebuilding the isolation boundary across three separate point releases rather than a single hotfix or content filter.[0]
The CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H indicates network-reachable, low-complexity attack requiring no user interaction and only low privileges, with a changed scope and high confidentiality, integrity, and availability impact.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| GitLab AI Gateway (18.x series) | 18.1.6 through before 19.2.4 | Fixed in 19.2.4[0] |
| GitLab AI Gateway (19.3 series) | 19.3 through before 19.3.2 | Fixed in 19.3.2[0] |
| GitLab AI Gateway (19.4 series) | 19.4 through before 19.4.1 | Fixed in 19.4.1[0] |
| GitLab.com hosted AI Gateway and GitLab Dedicated | Not applicable | Already protected; no customer action required[0] |
Key takeaways
- CVE-2026-90970 is a sandbox escape, not prompt injection: it changes what the model's output can actually touch on the host, a more fundamental and damaging failure than manipulating model behavior.[0]
- The CVSS 9.9 score falls just short of 10.0 only because an authenticated Duo Agent Platform account is required, but that caveat is weak inside development organizations where such accounts are numerous by design.[0]
- The vulnerability spanned three release branches (18.1.6 through 19.4), indicating a long-standing weakness in a newer component rather than a single-release regression.[0]
- Low attack complexity and no required user interaction make the patch an attractive candidate for patch-diffing, so defenders should treat the current absence of exploitation as temporary.[0]
Defensive actions
- Upgrade self-hosted AI Gateway immediately to 19.2.4, 19.3.2, or 19.4.1 depending on the running branch.: There is no supported workaround that fully closes the sandbox-escape path short of patching, and the flaw is rated CVSS 9.9.[0]
- Audit who currently holds Duo Agent Platform access and enforce least privilege.: The authentication requirement is the sole gate between an account compromise and command execution, and such access is often granted broadly to engineering staff.[0]
- Review AI Gateway host network placement and tighten segmentation from CI/CD runners, secrets managers, and source repositories.: A sandbox escape on a gateway co-located with sensitive build infrastructure inherits a large blast radius covering secrets and credentials.[0]
- Retroactively review logs for unusual flow-configuration changes or AI Gateway process activity between deployment of a vulnerable version and the October 2 patch date.: Helps detect possible exploitation despite no confirmed in-the-wild activity being reported.[0]
- Confirm which AI Gateway version runs in production and add explicit AI Gateway version tracking to vulnerability management inventory.: AI infrastructure is often deployed outside normal change-management, allowing such components to slip through patch cycles.[0]