In short: On October 2, 2026, GitLab shipped patches for CVE-2026-90970, a critical 9.9-out-of-10 vulnerability in its own AI Gateway — the service that powers GitLab Duo's AI features on self-hosted installations. An authenticated user with access to the Duo Agent Platform could craft a specific flow configuration to escape the prompt-template sandbox and execute arbitrary commands on the gateway server. There is no workaround — updating to a fixed release is the only fix.
What exactly is broken
AI Gateway processes custom prompt flow templates inside an isolated sandbox — the environment where the text sent to the model gets assembled. The flaw is tracked as CWE-1336 (improper neutralization of special elements used in a template engine): an authenticated user with Duo Agent Platform access could construct a flow configuration that broke out of that sandbox and ran arbitrary commands directly on the gateway host, rather than staying contained as the architecture intends.
Affected are AI Gateway versions from 18.1.6 before 19.2.4, from 19.3 before 19.3.2, and from 19.4 before 19.4.1. Fixed releases are 19.2.4, 19.3.2, and 19.4.1. GitLab has already updated its own hosted gateways; owners of self-hosted deployments — AI Gateway ships separately as a Docker image or Helm chart — need to update the component manually.
Why this isn't just "another SaaS bug"
What makes this case notable is that it's not a classic web-app vulnerability — it's a break in the isolation mechanism meant to keep an AI agent confined to safe, sandboxed execution. It's the same category of risk we covered in our piece on AI browser privacy risks: the more autonomy an assistant has inside your infrastructure, the more expensive a sandbox failure becomes. Here, the cost of failure isn't one leaked conversation — it's full command execution on the server of a company using GitLab Duo to automate development.
Ordinary GitLab.com users faced no exposure — the company closed the issue on its own hosted gateways before public disclosure. Only organizations running AI Gateway as part of a self-hosted or dedicated GitLab installation were ever at risk.
What this means in practice
For teams running self-hosted GitLab with AI Gateway enabled, this isn't a "keep an eye on it" advisory — it's an action item with no temporary mitigation besides updating to a patched release. For everyone else, it's another reminder that AI tooling bolted onto everyday enterprise services — code repositories, task trackers, chat — expands the attack surface just like any other infrastructure component, and its isolation deserves the same scrutiny as the code itself.
How to reduce the risk today
- Check your AI Gateway version. If you run self-hosted or dedicated GitLab with Duo Agent Platform enabled, update to 19.2.4, 19.3.2, or 19.4.1 immediately — there's no workaround.
- Restrict who has Duo Agent Platform access. The flaw requires an authenticated user, so keep the list of people who can build custom flows to the minimum necessary.
- Audit permissions for AI tooling in general. The same logic applies to any plugin or extension that gives a model access to files, a terminal, or the network — see our breakdown of risky browser extensions for the same "more access equals more attack surface" principle.
- Encrypt the channel your team uses to reach remote servers. A VPN won't fix a flaw in the gateway's own code, but on public Wi-Fi — a café, airport, coworking space — it closes a separate risk: traffic interception at the network level while you're administering infrastructure remotely. LiMP VPN is a no-logs service for Android, Windows and Chrome.
FAQ
A few quick answers to the questions this kind of critical AI-tooling vulnerability usually raises.
Sources
- The Hacker News — "GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers," October 2, 2026
- BleepingComputer — "GitLab warns of critical RCE vulnerability in AI Gateway service," October 2, 2026
- Security Affairs — "CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed"
