GitLab has fixed a critical vulnerability in its AI Gateway service that could allow an authenticated user with basic privileges and Duo Agent Platform access to execute arbitrary commands on an unpatched instance. Tracked as CVE-2026-90970, the issue affects self-hosted AI Gateway deployments under specific conditions.
The vulnerability involves improper neutralization of input. A specially crafted flow configuration could allow an authenticated user to escape the prompt template sandbox used by the AI Gateway, leading to command execution on the service. The available evidence describes the potential impact, but does not establish that CVE-2026-90970 has been exploited in the wild.
Affected and fixed versions
GitLab’s vulnerability record identifies affected AI Gateway versions as:
- 18.1.6 through versions before 19.2.4
- 19.3 before 19.3.2
- 19.4 before 19.4.1
GitLab addressed the issue in versions 19.2.4, 19.3.2, and 19.4.1. These fixes apply to customers running their own AI Gateway through GitLab Self-Managed and GitLab Duo Self-Hosted.
Customers using GitLab’s hosted AI Gateway on GitLab.com or GitLab Dedicated are described as already protected and do not need to take action for this issue. Organizations running a self-hosted instance should identify the deployed AI Gateway version and upgrade to one of the fixed releases as soon as possible. GitLab said it had contacted self-hosted AI Gateway customers before the public advisory.
Why it matters
AI Gateway provides access to AI-native GitLab Duo features, so it may sit within development environments that can reach internal services or sensitive project resources. The issue is limited by the requirement for authentication, relevant privileges, and Duo Agent Platform access, but successful command execution on the gateway could still expand the consequences of a compromised or misused account.
The evidence does not provide additional indicators of compromise, log locations, or temporary mitigations. Administrators should therefore focus on confirming whether they operate a self-hosted AI Gateway and checking that it runs 19.2.4, 19.3.2, 19.4.1, or a later release where applicable.
GitLab’s AI Gateway installation documentation and patch release notice provide the relevant deployment and release context. BleepingComputer’s report contains additional coverage of the advisory.
Alex Mira is a fictitious AI-assisted author created for the Toolslib blog. Designed to support cybersecurity education, Alex writes about malware trends, software utilities, privacy practices, Windows internals, and practical defensive workflows. Articles published under Alex’s name are generated or assisted by AI and reviewed according to Toolslib’s editorial standards before publication.
Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!