GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways
EditorialBy TrustList Editorial
GitLab fixed CVE-2026-90970, rated 9.9, in its self-hosted AI Gateway: a user with Duo Agent Platform access could escape the sandbox through a custom flow prompt template and run commands. Fixed in 19.2.4, 19.3.2 and 19.4.1.
- Cybersecurity
- Vulnerability Management
- Patch Management
- DevOps
- +2 more
About GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways
GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways
2 October 2026 — GitLab has released fixes for a critical vulnerability in its AI Gateway, the service that connects GitLab's AI features, including the Duo Agent Platform, to language models. CVE-2026-90970 is rated 9.9 out of 10. GitLab describes it as an improper neutralisation issue in the custom flow prompt template: an authenticated user with access to the Duo Agent Platform could escape the sandbox with a crafted flow configuration and run arbitrary commands on the AI Gateway. BleepingComputer reported the release on 2 October 2026.
Not yet independently verified. GitLab’s patch-release page carries no publication date; we date it to the day we read it, 2 October 2026. No exploitation has been reported. We will update this when it can be confirmed, and remove this note.
Who is affected
- Affected: self-hosted AI Gateway versions 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, and 19.4.0.
- Fixed: 19.2.4, 19.3.2 and 19.4.1.
- Already protected: GitLab.com, GitLab Dedicated, and self-managed GitLab instances that use the GitLab-hosted AI Gateway. The risk is for organisations that run the AI Gateway themselves, usually to keep code and prompts on their own infrastructure or to use their own models.
GitLab gives no workaround.
Why it matters
An AI Gateway sits between developers, source code and model providers, and often holds the credentials for those models and for internal services the agents call. Command execution on it can expose model keys, prompts containing source code, and whatever the gateway can reach on the network. The flaw needs only an authenticated user with Duo Agent Platform access, which in many organisations is every developer. It is one more case of agent platforms widening who can run code where.
What to do
- Upgrade every self-hosted AI Gateway to 19.2.4, 19.3.2 or 19.4.1, matching your GitLab line, as soon as possible.
- Rotate secrets the gateway holds, such as model-provider API keys, if it was exposed to many users before patching.
- Review custom flows created recently in the Duo Agent Platform, and who can create them.
- Run the gateway with minimal privileges and network reach: it does not need access to production systems.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- DevOps
- Source Code Management Software
- Artificial Intelligence - AI
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.