GitLab Patches Critical AI Gateway Flaw
GitLab has released critical security patches for its AI Gateway to address a vulnerability that could allow authenticated users to execute unauthorized commands.

GitLab has deployed critical security updates to address a severe vulnerability in its AI Gateway, tracked as CVE-2026-90970. The release of these patches aims to prevent unauthorized command execution on affected systems, specifically targeting self-hosted environments. To resolve the issue, GitLab has rolled out updates across several versions of the gateway, ensuring that the underlying flaw is neutralized for users who apply the fixes.
According to GitLab, the vulnerability allows an authenticated user with Duo Agent Platform access to bypass the prompt template sandbox and execute arbitrary commands under certain conditions. The security researcher invisiblemeerkat responsibly disclosed this vulnerability to GitLab via the HackerOne bug bounty platform. Before releasing the public security advisory, GitLab proactively conducted targeted outreach to customers operating self-hosted gateways to warn them of the security risk.
This security update matters because only organizations hosting their own AI Gateway must manually apply the patches to secure their environments. GitLab has already patched its own hosted gateways, which automatically protects customers on GitLab.com, GitLab Dedicated, and connected self-managed instances without requiring administrative action on their part. The vulnerability is resolved in AI Gateway versions 19.2.4, 19.3.2, and 19.4.1.
Regarding external assessments, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has analyzed the threat landscape for this vulnerability. CISA currently lists the active exploitation status of CVE-2026-90970 as none, indicating there is no public evidence of malicious actors leveraging this specific loophole.
Despite the release of the patches, several details remain unknown. The official advisory does not describe the specific conditions needed to trigger the sandbox escape, nor does it name any specific user roles beyond general Duo Agent Platform access. Furthermore, there is no provided workaround for self-hosted gateways that cannot be immediately updated, and GitLab has not provided a method for administrators to check if a gateway was compromised prior to applying the update.
Sources
- The Hacker NewsPage Not Found – The Hacker News
- The Hacker NewsGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
- BleepingComputerGitLab warns of critical RCE vulnerability in AI Gateway service
- GitLab DocsGitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1
- Welcome to COE Security | AI Cyber Security Solutions CompanyCritical GitLab AI Gateway Vulnerability Highlights the Security Risks of AI Powered Development -
- ForkastGitLab Patches Critical AI Gateway RCE Vulnerability — Prompt Template Sandbox Escape Rated CVSS 9.9
Verified claims
Stills


Written by The Quiet Search. Method: /about.