GitLab's AI Gateway Sandbox Escape Ends in Command Execution on Self-Hosted Instances

CVE-2026-90970 lets an authenticated user with Duo Agent Platform access escape the GitLab AI Gateway's prompt template sandbox through a crafted flow configuration, and run arbitrary comman

Netics editorial card for the GitLab AI Gateway CVE-2026-90970 sandbox escape analysis.
Netics editorial card on GitLab AI Gateway CVE-2026-90970: a prompt template sandbox escape that ends in command execution on self-hosted gateways.

TL;DR

  • GitLab has patched CVE-2026-90970, an issue in the GitLab AI Gateway that could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox through a specially crafted flow configuration, leading to arbitrary command execution on the gateway.
  • The severity is rated CVSS 9.9 with a scope change in the vector, and the affected range runs from AI Gateway 18.1.6 to 19.2.3, from 19.3.0 to 19.3.1 and from 19.4.0. The fixed releases are 19.2.4, 19.3.2 and 19.4.1.
  • GitLab-hosted AI Gateways were patched before the release note, so GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted AI Gateway need no action. The exposure sits with self-managed customers running their own self-hosted gateway.
  • The operational lesson is inventory-related: the AI Gateway is a separate service with its own version line, and a GitLab core version check tells you nothing about the gateway that is running alongside it.

What CVE-2026-90970 allows

The vendor's own description is compact and precise, so it is worth reading as written: GitLab remediated an issue in the AI Gateway that, under certain conditions, "could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway."

Netics editorial diagram: the CVE-2026-90970 remediation sequence
Netics editorial sequence grounded in GitLab's patch release note: a crafted flow configuration escapes the prompt template sandbox, the fix lands in AI Gateway 19.2.4, 19.3.2 and 19.4.1, and the verification step is the gateway version on your own host.

Read that carefully, because it frames the whole incident. The attacker is authenticated. No anonymous request is involved. What is manipulated is a flow configuration, which is ordinary user-facing content in the Duo Agent Platform: prompt templates and multi-step flows are things developers are expected to author. The sandbox around those templates is the control that keeps an authored flow inside the process it was meant to be, and the defect lets a crafted configuration leave it.

The severity assessment matches that reading. CVSS 9.9 with a scope change means the impact escapes the vulnerable component's own security authority rather than staying inside it, with high confidentiality, integrity and availability impact across the triad. The responsible disclosure credit goes to a HackerOne researcher.

Why the AI Gateway holds privileged material

A gateway that sits between a development platform and one or more model providers is not a passthrough. It is a service that holds credentials for those providers, terminates requests from the platform, and in a self-hosted deployment owns the whole inference path: no prompt, code input or model response leaves the customer network, which is exactly why organisations choose it.

Official GitLab capture: AI Gateway critical patch release
Official GitLab documentation capture (docs.gitlab.com, retrieved 2026-10-04): the AI Gateway critical patch release note recommending that self-managed customers with self-hosted AI Gateway installations upgrade to 19.2.4, 19.3.2 or 19.4.1 immediately.

That design decision is the reason this vulnerability deserves attention beyond its CVSS number. Command execution on the gateway is command execution inside the component that holds the keys to every model the platform talks to, and inside the component that sees every prompt and every response. Scope, in other words, is a description of the blast radius a security team would have to bound after a successful exploit.

GitLab's documentation separates the deployment options explicitly. A self-hosted AI Gateway with self-hosted models operates inside your own infrastructure with full control over the AI path. A hybrid configuration mixes a self-hosted gateway with GitLab-managed models per feature. The GitLab.com AI Gateway with vendor models requires no additional infrastructure at all. Each option carries its own maintenance obligation, and only the first two put the gateway version under your own change control.

Confirm the gateway version on your own host

The remediation is a version upgrade, and the verification is the part teams get wrong. GitLab states that a fix has already been deployed for GitLab-hosted AI Gateways, and that customers on GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted AI Gateway are protected. Everyone else has to look at the gateway itself.

Netics editorial diagram: what the advisory measures
Netics editorial scorecard from the GitLab patch release note: CVSS 9.9 with a scope-changing vector, an authenticated Duo Agent Platform user as the access requirement, the affected gateway ranges, and GitLab-hosted gateways already patched.

Two consequences follow. First, an upgrade of the GitLab application does not necessarily move the AI Gateway, because the two have separate release lines; the patched versions are named with gateway version numbers. Second, an inventory that lists "GitLab" as a single item will hide the component that matters here. If the gateway runs as a container or a service beside the application you already patch, it needs its own entry, its own version field and its own upgrade owner.

The remediation order for a self-managed gateway

Start with identification, because it decides whether the rest of the work applies. Find every place a self-hosted AI Gateway is running, note the version, and record whether any feature routes to the GitLab-hosted gateway instead: GitLab documents a hybrid mode in which some features use managed models, and those features sit outside your gateway entirely.

Then upgrade the affected gateways to the fixed releases, in the branch that matches your deployment. GitLab's note recommends the update immediately, with the caveat that self-managed customers were contacted before publication, so a team that follows its vendor notifications may already know about this one.

Then treat the gateway as a privileged component in your own documentation. Rotate any provider credentials the gateway holds if you cannot establish that the upgrade landed promptly, keep the gateway's logs where your monitoring can see them, and add a version check to whatever inventory report you produce every month. A gateway that appears in no inventory will keep failing the same check, silently, patch after patch.

Official GitLab capture: Duo self-hosted models documentation
Official GitLab documentation capture (docs.gitlab.com/administration/gitlab_duo_self_hosted, retrieved 2026-10-04): the GitLab Duo self-hosted models page, which lays out the deployment topologies in which a customer operates their own AI Gateway inside their own network.

What a self-hosted AI platform adds to your attack surface

Take a concrete case, marked as hypothetical. A 30-person product team moves Duo to a self-hosted AI Gateway for data-residency reasons: code and prompts must stay on infrastructure inside the EU, and the gateway is the component that makes that true. Nothing about the deployment is wrong. What changes is the inventory: a service that did not exist in their patching calendar a year ago now sits on the path of every code suggestion, holds credentials for the model backend, and has its own release line.

That last part generalises to every AI component a development platform now ships. An inference gateway, a retrieval index, a vector store, an agent runtime: each one is a service with a version, a credential set and a CVE feed of its own. Treating them as features of the platform they plug into is what makes a plausible upgrade story turn into an unpatched gateway running behind a patched application, and noticing that state is a monitoring problem rather than a scanning problem, which is where infrastructure monitoring with plain-language alerts does its work.

Netics editorial diagram: how GitLab describes the issue
Netics editorial visual quoting the vendor's description of CVE-2026-90970 from the AI Gateway patch release note: an authenticated Duo Agent Platform user escaping the prompt template sandbox through a crafted flow configuration, up to arbitrary command execution on the AI Gateway.

The wider pattern is one we have written about on the coding agent supply chain: as development platforms absorb AI features, the AI components become the parts an attacker probes, because they are newer than the application around them and hold credentials the application never needed. The fix here is available and simple to verify. The work that remains is making sure the gateway is something your team knows it runs.

Sources

Source: GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1 — docs.gitlab.com (no publication date on the page; retrieved 2026-10-04). All technical details in this article come from that note: the vendor's description of CVE-2026-90970, the CVSS 9.9 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, the affected ranges from 18.1.6, the fixed releases 19.2.4 / 19.3.2 / 19.4.1, the statement that GitLab-hosted AI Gateways are already patched, and the targeted outreach to self-hosted customers. Source: GitLab Duo self-hosted administration documentation — docs.gitlab.com/administration/gitlab_duo_self_hosted (self-hosted, hybrid and GitLab.com AI Gateway configurations, and the statement that inference data, code inputs, model prompts and model responses stay inside the customer network in a fully self-hosted setup). Internal linkage: Plugin4Shell and the coding agent supply chain. More security engineering analysis on neticslabs.com.

Source: GitLab AI Gateway patch release note — docs.gitlab.com, retrieved 2026-10-04. Captures: official GitLab AI Gateway patch release and Duo self-hosted pages, retrieved 2026-10-04.