Skip to content
TrustList
News

GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways

Editorial

By TrustList Editorial

GitLab fixed CVE-2026-90970, rated 9.9, in its self-hosted AI Gateway: a user with Duo Agent Platform access could escape the sandbox through a custom flow prompt template and run commands. Fixed in 19.2.4, 19.3.2 and 19.4.1.

About GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways

GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways

2 October 2026 — GitLab has released fixes for a critical vulnerability in its AI Gateway, the service that connects GitLab's AI features, including the Duo Agent Platform, to language models. CVE-2026-90970 is rated 9.9 out of 10. GitLab describes it as an improper neutralisation issue in the custom flow prompt template: an authenticated user with access to the Duo Agent Platform could escape the sandbox with a crafted flow configuration and run arbitrary commands on the AI Gateway. BleepingComputer reported the release on 2 October 2026.

Not yet independently verified. GitLab’s patch-release page carries no publication date; we date it to the day we read it, 2 October 2026. No exploitation has been reported. We will update this when it can be confirmed, and remove this note.

Who is affected

  • Affected: self-hosted AI Gateway versions 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, and 19.4.0.
  • Fixed: 19.2.4, 19.3.2 and 19.4.1.
  • Already protected: GitLab.com, GitLab Dedicated, and self-managed GitLab instances that use the GitLab-hosted AI Gateway. The risk is for organisations that run the AI Gateway themselves, usually to keep code and prompts on their own infrastructure or to use their own models.

GitLab gives no workaround.

Why it matters

An AI Gateway sits between developers, source code and model providers, and often holds the credentials for those models and for internal services the agents call. Command execution on it can expose model keys, prompts containing source code, and whatever the gateway can reach on the network. The flaw needs only an authenticated user with Duo Agent Platform access, which in many organisations is every developer. It is one more case of agent platforms widening who can run code where.

What to do

  • Upgrade every self-hosted AI Gateway to 19.2.4, 19.3.2 or 19.4.1, matching your GitLab line, as soon as possible.
  • Rotate secrets the gateway holds, such as model-provider API keys, if it was exposed to many users before patching.
  • Review custom flows created recently in the Duo Agent Platform, and who can create them.
  • Run the gateway with minimal privileges and network reach: it does not need access to production systems.

Sources

Categories & features