GitLab AI Gateway CVE-2026-90970 (CVSS 9.9): Duo Agent prompt-template sandbox escape → auth’d RCE — patch 19.2.4/19.3.2/19.4.1
GitLab AI Gateway critical patch release (2 October 2026; Docs advisory) remediates CVE-2026-90970 (CVSS 3.1 9.9; AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): improper neutralization in a custom flow prompt template that, under certain conditions, lets an authenticated user with Duo Agent Platform access escape the prompt-template sandbox via a crafted flow configuration and execute arbitrary commands on the AI Gateway. Impacted: AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Fixed: 19.2.4, 19.3.2, 19.4.1. GitLab-hosted AI Gateways (GitLab.com, Dedicated, Self-Managed using GitLab-hosted gateway) already patched — no action. Self-Hosted AI Gateway on Self-Managed: upgrade immediately; GitLab says it conducted targeted pre-disclosure outreach to those customers. Credit: invisiblemeerkat. Distinct from prior desk GitLab CE/EE path-traversal CVE-2026-85706 (KEV). Primary: GitLab Docs AI Gateway patch release; wire: BleepingComputer 2 Oct.
- Product
- GitLab Self-Hosted AI Gateway (GitLab Duo / Duo Agent Platform)
- Versions
- Affected: AI Gateway ≥18.1.6 <19.2.4; 19.3 <19.3.2; 19.4 <19.4.1. Fixed: 19.2.4, 19.3.2, 19.4.1. GitLab-hosted gateways already remediated.
- CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade Self-Hosted AI Gateway to 19.2.4, 19.3.2, or 19.4.1 per GitLab Docs. GitLab.com / Dedicated / Self-Managed using GitLab-hosted AI Gateway: no action.
Primary: GitLab Docs — AI Gateway critical patch release 19.2.4 / 19.3.2 / 19.4.1 (CVE-2026-90970; 2 Oct 2026) · Vendor: GitLab — Self-Hosted AI Gateway security fix advisory · CVE: CVE-2026-90970, CVE-2026-85706 · BleepingComputer — GitLab warns of critical RCE in AI Gateway (2 Oct 2026)
