Overview
- GitLab disclosed the issue on October 2 and released patched AI Gateway builds 19.2.4, 19.3.2, and 19.4.1 while saying its GitLab-managed gateways have already been remediated.
- The flaw, tracked as CVE-2026-90970 and rated critical with a 9.9 CVSS score, lets an authenticated user with Duo Agent Platform access escape a prompt-template sandbox and execute arbitrary commands on a vulnerable gateway.
- Only customers running self-hosted AI Gateway installations need to act because GitLab.com, GitLab Dedicated, and instances using GitLab-hosted gateways were fixed by the company.
- CISA added a note to the CVE record saying it has observed no exploitation, but GitLab’s advisory does not provide detection steps or a workaround for gateways that cannot be updated yet.
- A compromised self-hosted gateway could expose JWT signing keys and connections to internal GitLab instances and AI providers, which could give attackers a foothold inside an organization and make rapid patching essential.