CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970 is a vulnerability in the GitLab AI Gateway that stems from improper handling of custom flow prompt templates used by the Duo Agent Platform. The flaw can allow specially crafted template content to escape the restrictions of the prompt template sandbox, which is intended to prevent untrusted template logic from interacting with the underlying execution environment. The issue is particularly significant for organizations operating Self-Hosted AI Gateway deployments because exploitation takes place within infrastructure controlled by the organization.
Under certain conditions, an authenticated user with access to the Duo Agent Platform could submit a specially crafted flow configuration containing malicious template elements. Improper processing of these elements could allow the attacker to break out of the security restrictions imposed by the prompt template sandbox. Successful exploitation could result in arbitrary command execution on the AI Gateway, potentially giving the attacker access to resources and sensitive information available to the gateway process. Depending on the gateway's privileges and deployment configuration, compromise could affect the confidentiality, integrity, and availability of the service and resources accessible from its execution environment.
Vulnerability Details
| CVE ID | Severity | CVSS Score | EPSS Score | Impact |
|---|---|---|---|---|
| CVE-2026-90970 | Critical | 9.9 | 0.94% | Arbitrary Command Execution |
Technical Analysis
The GitLab AI Gateway operates as an intermediary between GitLab's AI-powered functionality and the underlying large language models. It handles requests originating from GitLab, performs AI-related processing and prompt preparation, and communicates with configured model providers. GitLab supports both hosted and self-hosted AI Gateway deployments, allowing organizations to operate the gateway within their own infrastructure when required.The vulnerability results from improper neutralization of special elements used within a template engine. When attacker-controlled data from a custom flow configuration reaches the vulnerable template-processing mechanism, specially constructed template elements may not be sufficiently sanitized or constrained before evaluation. This weakness is classified as CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine.
An authenticated user with access to the Duo Agent Platform could exploit this weakness by creating a malicious flow configuration designed to interfere with template evaluation. Under the required conditions, the crafted configuration could escape the intended prompt template sandbox, crossing the security boundary intended to restrict what a prompt template can execute or access.
Impact
- Arbitrary Command Execution: Successful exploitation could allow an authenticated attacker to escape the prompt template sandbox and execute arbitrary commands on the affected AI Gateway.
- AI Gateway Compromise: Command execution could provide an attacker with a foothold on infrastructure hosting the GitLab Self-Hosted AI Gateway.
- Sensitive Information Exposure: A compromised gateway could expose information accessible to the AI Gateway process, depending on the deployment configuration and privileges assigned to the service.
- Authentication Material at Risk: Sensitive authentication-related material accessible from the compromised gateway environment could potentially be exposed.
Affected Versions
| Affected GitLab AI Gateway Version | Fixed Version |
|---|---|
| 18.1.6 through 19.2.3 | 19.2.4 |
| 19.3.0 through 19.3.1 | 19.3.2 |
| 19.4.0 | 19.4.1 |
MITRE ATT&CK Mapping
| Tactic | Technique | Technique ID | Description |
|---|---|---|---|
| Initial Access | Exploit Public-Facing Application | T1190 | An authenticated attacker with access to the Duo Agent Platform could exploit the vulnerable GitLab Self-Hosted AI Gateway using a specially crafted flow configuration that triggers the prompt template sandbox escape. |
| Execution | Command and Scripting Interpreter | T1059 | Successful exploitation of CVE-2026-90970 can result in arbitrary command execution within the context of the affected GitLab AI Gateway service. |
Mitigation
- Upgrade the GitLab Self-Hosted AI Gateway: Organizations running affected installations should upgrade to 19.2.4, 19.3.2, 19.4.1, or a later supported release containing the security fix.
- Identify Self-Hosted AI Gateway Deployments: Determine whether GitLab environments use a GitLab-hosted or Self-Hosted AI Gateway and prioritize affected self-hosted installations.
- Review Duo Agent Platform Access: Review accounts with access to the Duo Agent Platform and remove unnecessary permissions to reduce the number of users capable of reaching the vulnerable functionality.
- Review Custom Flow Configurations: Examine custom flows for unexpected or unauthorized configurations, particularly configurations created or modified by unusual accounts.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




