Threat · curated 2 Oct 2026
GitLab warns of critical RCE vulnerability in AI Gateway service
First reported bleepingcomputer.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-90970 shows that AI agent gateways introduce a new prompt-template sandbox-escape attack surface where crafted agent flow configurations can lead to full RCE on infrastructure hosting LLM features.
GitLab disclosed CVE-2026-90970, a critical remote code execution flaw in its AI Gateway service that powers GitLab Duo features. An authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on the AI Gateway; GitLab released fixed versions 19.2.4, 19.3.2, and 19.4.1 for self-hosted deployments.