GitLab has issued an urgent security advisory warning administrators of a critical vulnerability affecting its AI Gateway service. The security flaw, which has been assigned the identifier CVE-2026-90970, carries a maximum severity CVSS score of 9.9 out of 10 and could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands directly on the underlying gateway under specific operational conditions.

The discovery has prompted an immediate response from the DevOps platform provider, which has already deployed patches for cloud-managed environments. However, organizations hosting their own infrastructure must take immediate manual steps to secure their systems.

The AI Gateway serves as the critical infrastructural bridge connecting a GitLab instance to various artificial intelligence models and processing pipelines. Because GitLab operates AI Gateways on behalf of its customers across major cloud offerings, the company has already mitigated the risk for users on GitLab.com, GitLab Dedicated, and self-managed instances that rely exclusively on a GitLab-hosted gateway. According to the advisory, these managed environments require no direct user intervention.

The exposure is strictly limited to organizations that have chosen to host their own gateway instances. GitLab offers this self-hosted deployment option specifically for enterprises and regulated industries that need to keep their artificial intelligence request and response data strictly within their own private environments. For these self-hosted deployments, GitLab is strongly urging administrators to update their software immediately, noting that guidance was distributed to affected enterprise customers prior to the public disclosure of the vulnerability.

Disclosed officially on October 2, 2026, the vulnerability has not yet been linked to active exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency evaluated the CVE record on the day of its release and categorized the current threat level of active exploitation as none. This classification indicates that while a severe flaw exists, security agencies have not observed threat actors actively weaponizing the bug in real-world attacks, nor is there a public proof-of-concept exploit widely circulating at this stage.

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Despite the absence of confirmed attacks, security researchers emphasize that the severity of the vulnerability leaves little room for complacency. A self-hosted gateway typically holds sensitive cryptographic assets, including signing keys for JSON Web Tokens, which must be protected as high-value credentials. Furthermore, the gateway maintains active network connections to the primary GitLab instance and external artificial intelligence model providers, making it a critical pivot point if compromised.

The vulnerability stems from a prompt template weakness located within a custom flow, corresponding to a classic template engine vulnerability class tracked as CWE-1336. On the Duo Agent Platform, users can create custom flows, which are specialized artificial intelligence-powered workflows designed to automate complex, multi-step engineering and operational tasks.

According to GitLab’s analysis, a logged-in user who possesses legitimate access to the Duo Agent Platform can exploit the flaw by supplying a specially crafted flow configuration. This malicious input allows the user to successfully escape the designated prompt template sandbox environment. Once the sandbox boundary is broken, the attacker can achieve arbitrary command execution directly on the gateway infrastructure hosting the service.

The specific operational conditions required to successfully execute the attack have not been fully detailed in the advisory, and the company did not specify whether attackers require any particular elevated user role beyond standard access to the Duo Agent Platform.

The vulnerability affects multiple recent iterations of the AI Gateway software. Because the gateway is distributed independently as its own Docker image or Helm chart rather than being bundled directly into the core GitLab monolithic release, it follows a distinct update lifecycle.

The software updates address the flaw across three maintained product lines. Organizations running gateway versions from 18.1.6 up to, but not including, 19.2.4 must upgrade to version 19.2.4. For users operating within the 19.3 branch, version 19.3.2 contains the necessary security fixes. Similarly, deployments running the 19.4 series must be updated to version 19.4.1.

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Every gateway release predating version 19.2.4—stretching back through the entire 18.1.6 and subsequent 19.1 development lines—falls into the vulnerable range. GitLab’s standard maintenance policy dictates that security fixes are primarily backported to the three most recent minor release lines, which currently align with versions 19.4, 19.3, and 19.2.

Administrators responsible for Docker-based deployments must stop and remove their currently running container instances before pulling and executing the updated image tags corresponding to the fixed versions. For environments managed via Helm charts, operators must update the respective image tag settings within their configuration templates.

At the time of the advisory’s release, GitLab provided no temporary workarounds or mitigation strategies for organizations unable to apply the patches immediately. Additionally, the software provider noted that there are currently no reliable forensic indicators or logs provided to help administrators determine whether a gateway instance was compromised prior to the application of the security patches.

The discovery of CVE-2026-90970 follows a strikingly similar security incident earlier in the year. In February, GitLab issued emergency patches for another critical gateway vulnerability tracked as CVE-2026-1868. That flaw also received a severe CVSS rating of 9.9 and could be triggered by an authenticated user via a crafted flow definition, ultimately leading to denial of service or remote code execution on the gateway.

Both security events highlight ongoing architectural challenges involving template engines and automated workflow processing within modern artificial intelligence integration layers. The latest flaw was responsibly reported to GitLab through their HackerOne bug bounty program by a security researcher identified by the handle invisiblemeerkat.

Leave a Reply

Your email address will not be published. Required fields are marked *