Threat · curated 2 Oct 2026

GitLab warns of critical RCE vulnerability in AI Gateway service

Coverage timeline

2 Oct 2026bleepingcomputer.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-90970 shows that AI agent gateways introduce a new prompt-template sandbox-escape attack surface where crafted agent flow configurations can lead to full RCE on infrastructure hosting LLM features.

GitLab disclosed CVE-2026-90970, a critical remote code execution flaw in its AI Gateway service that powers GitLab Duo features. An authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on the AI Gateway; GitLab released fixed versions 19.2.4, 19.3.2, and 19.4.1 for self-hosted deployments.