GitLab Patches Critical AI Gateway Flaw CVE-2026-90970: Crafted Duo Agent Platform Flows Could Escape the Prompt Template Sandbox and Run Commands

GitLab Patches Critical AI Gateway Flaw CVE-2026-90970: Crafted Duo Agent Platform Flows Could Escape the Prompt Template Sandbox and Run Commands

GitLab Patches Critical AI Gateway Flaw CVE-2026-90970: Crafted Duo Agent Platform Flows Could Escape the Prompt Template Sandbox and Run Commands

GitLab disclosed on October 2 that a critical flaw in its AI Gateway could let a logged-in user with Duo Agent Platform access run arbitrary commands on the gateway under certain conditions. The vulnerability, tracked as CVE-2026-90970 (CVSS 9.9), is a prompt template escape: a user could "escape the prompt template sandbox via a specially crafted flow configuration," GitLab said, leading to arbitrary command execution on the gateway service — the component that connects a GitLab instance to AI models. A custom flow is an AI-powered workflow built on the Duo Agent Platform to automate multi-step tasks, and the flaw sits in the prompt template those flows use.

Only organizations that host their own gateway need to act. GitLab runs AI Gateways for its customers and has already fixed them — customers on GitLab.com, GitLab Dedicated, and self-managed instances that use the GitLab-hosted gateway are protected. But self-managed customers who chose a self-hosted gateway — the option that keeps AI request and response data inside the customer's own environment — are strongly recommended to update immediately. The gateway ships as its own Docker image or Helm chart with its own update steps, and it is affected from version 18.1.6 up to (but not including) 19.2.4. Fixes are gateway versions 19.2.4, 19.3.2, and 19.4.1; no fixed version exists below 19.2.4, no workaround is listed, and the advisory offers no way to check whether a gateway was attacked before it was updated. CISA's October 2 assessment lists exploitation as "none." The flaw was reported by HackerOne user invisiblemeerkat.

What makes command execution on an AI Gateway serious: a self-hosted gateway holds JSON Web Token signing keys — which GitLab's install documentation says must be treated as sensitive credentials — and it maintains connections both to the GitLab instance and to the organization's AI model providers. Docker deployments update by stopping and removing the running container and pulling a new image tag (for example self-hosted-v19.4.1-ee); Helm deployments set the new tag in the chart's image setting.

This is the second critical template-expansion flaw in the gateway this year. In February, GitLab fixed CVE-2026-1868 (also CVSS 9.9, the same CWE-1336 template-engine weakness class): insecure template expansion of user-supplied data via crafted Duo Agent Platform flow definitions that could cause denial of service or code execution, fixed in gateway versions 18.6.2, 18.7.1 and 18.8.1 and discovered internally by GitLab's Joern Schneeweisz. Two nine-point-nine template escapes in one component in eight months is a pattern — and a reminder of how quickly GitLab attack surfaces get probed once public, as September's path-traversal zero-day proved when it was exploited within hours of disclosure.

What Should You Do?

  1. Upgrade any self-hosted AI Gateway to 19.2.4, 19.3.2 or 19.4.1 today, matching your maintained GitLab release line — GitLab's maintenance policy currently covers 19.4, 19.3 and 19.2.
  2. Treat the gateway's JWT signing keys as credentials that matter: if you have any suspicion of past access, rotate them — and review what those tokens could reach.
  3. Restrict who has Duo Agent Platform access. The flaw requires an authenticated user with that permission; that group should be small, known and audited.
  4. Network-isolate the gateway: it should talk to your GitLab instance and your model providers — nothing else. An exposed gateway is an admin-grade target with signing keys inside.

The WAF Angle

AI features have quietly expanded production perimeters: a service that holds signing keys and model-provider credentials grew out of what many teams still think of as "a GitLab plugin." The flaw class is familiar, though — prompt template escapes are server-side template injection's newest costume, where user-controlled input reaches a template engine and breaks out of it. The defenses rhyme with SSTF-era lessons: the AI request path deserves the same inline inspection, rate limiting and authentication scoping as any admin surface, and "the gateway is internal" is not a control when the flaw's entry requirement is just a normal authenticated session. With exploitation currently assessed as none but a Docker/Helm-deployed component that teams forgot they exposed, expect scanning to follow this advisory — the patch window is now, not when a KEV entry appears.

Sources