A critical vulnerability in GitLab’s AI Gateway has been identified, allowing a logged-in user with Duo Agent Platform access to execute commands on the gateway under specific circumstances. GitLab released an advisory addressing this issue.
The AI Gateway is responsible for connecting a GitLab instance to AI models, and only organizations hosting their own gateway need to take action. The vulnerability has been patched in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The vulnerability, identified as CVE-2026-90970, was disclosed by GitLab on October 2 and rated as critical with a CVSS score of 9.9 out of 10.
GitLab has already resolved the issue for its customers running AI Gateways. Customers using GitLab.com, GitLab Dedicated, and self-managed instances with GitLab-hosted gateways do not need to take any action.
Self-managed customers have the option to host their own gateway, a solution recommended by GitLab for maintaining AI request and response data within the customer’s environment. GitLab strongly advises self-managed customers to update immediately and has communicated this guidance to them prior to the advisory publication.
The advisory does not indicate any known exploitation of the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has assessed the CVE record, listing the exploitation as “none” as of October 2.
Affected and Fixed Versions
The following versions are AI Gateway versions, each installed as a Docker image or Helm chart with specific update procedures.
| Gateway version in use | First fixed version |
|---|---|
| 18.1.6 or later, before 19.2.4 | 19.2.4 |
| 19.3, before 19.3.2 | 19.3.2 |
| 19.4, before 19.4.1 | 19.4.1 |
To update a Docker deployment, stop and remove the running container, then pull and run the new image tag (e.g., self-hosted-v19.4.1-ee). Helm deployments require setting the new tag in the chart’s image setting.
No fixed version is available prior to 19.2.4, leaving all gateway releases from 18.1.6 through the 19.1 line vulnerable. GitLab advises administrators to match the gateway image with their GitLab minor version.
GitLab’s maintenance policy includes versions 19.4, 19.3, and 19.2 for security fixes, aligning with the gateway fix releases. No workarounds are provided for gateways awaiting updates.
Details of the Vulnerability
The vulnerability resides in the prompt template of a custom flow within the Duo Agent Platform, allowing a logged-in user with access to execute commands on the gateway by escaping the prompt template sandbox. The specific conditions required for the attack are not disclosed.
A self-hosted gateway stores sensitive JWT signing keys and connects to the organization’s AI model providers. GitLab acknowledges the reporting of the vulnerability by HackerOne user invisiblemeerkat.
In a previous instance, GitLab addressed another gateway flaw, CVE-2026-1868, also rated 9.9, allowing a logged-in user to execute code on the gateway through a crafted flow definition. Both vulnerabilities fall under the template engine weakness class CWE-1336.




