International Edition
Latest News
Technology

GitLab Patches Critical AI Gateway RCE Vulnerability (CVE-2026-90970)

A critical vulnerability carrying a 9.9 out of 10 CVSS score has been discovered in GitLab's AI Gateway, potentially allowing authenticated users to escape prompt template sandboxes and execute arbitrary commands on underlying hosts, as reported by thehackernews.com.…

GitLab Patches Critical AI Gateway RCE Vulnerability (CVE-2026-90970)

A critical vulnerability carrying a 9.9 out of 10 CVSS score has been discovered in GitLab’s AI Gateway, potentially allowing authenticated users to escape prompt template sandboxes and execute arbitrary commands on underlying hosts, as reported by thehackernews.com. Tracked as CVE-2026-90970, the flaw affects self-hosted organizations utilizing the Duo Agent Platform, requiring an immediate manual update to secure gateway installations against remote compromise.

GitLab Issues Critical Advisory for CVE-2026-90970

GitLab disclosed the critical security advisory on October 2, 2026, targeting the AI Gateway component that connects enterprise instances to external AI models. The vulnerability specifically impacts custom workflows created within the Duo Agent Platform. According to technical documentation reported by tech.yahoo.com, the flaw stems from insufficient sanitization of user-supplied flow configuration data processed through Jinja2-style template placeholders. An authenticated user with specific platform access can manipulate these placeholders to achieve a sandbox escape, leading to arbitrary command execution on the host operating system. The software defect belongs to the CWE-1336 template engine weakness class.

The severity of CVE-2026-90970 matches an earlier security incident from February 2026. At that time, GitLab fixed CVE-2026-1868, another CVSS 9.9 vulnerability discovered internally by team member Joern Schneeweisz, which also involved template expansion issues in the Duo Workflow Service component, as documented in official GitLab records. Security researchers note that the recurrence of this vulnerability class within an eight-month span highlights persistent isolation challenges in AI agent infrastructure layers.

Deployment Impact and Required Updates for Self-Hosted Gateways

The scope of remediation depends entirely on how an organization hosts its infrastructure. GitLab confirmed that instances hosted directly on GitLab.com, GitLab Dedicated, and self-hosted environments utilizing a GitLab-hosted gateway are already protected because patches were deployed automatically by the company, according to thehackernews.com. However, organizations operating their own self-hosted AI Gateways must manually update their Docker images or Helm charts.

Affected versions include every gateway release from 18.1.6 through the entire 19.1 line. To eliminate the risk, administrators must upgrade to specific fixed versions depending on their current deployment track:

  • Gateway versions 18.1.6 or later (before 19.2.4) must update to version 19.2.4.
  • Gateway versions 19.3 (before 19.3.2) must update to version 19.3.2.
  • Gateway versions 19.4 (before 19.4.1) must update to version 19.4.1.

For Docker deployments, administrators must stop and remove the running container before pulling and executing the new image tag. Helm deployments require setting the updated tag directly within the chart’s image configuration.

Exploitation Status and Sensitive Data Exposure Risks

Cybersecurity and Infrastructure Security Agency (CISA) list the active exploitation status of CVE-2026-90970 as “none,” with no public proof-of-concept exploits circulating. HackerOne user invisiblemeerkat received formal credit from GitLab for discovering and reporting the vulnerability.

Despite the lack of recorded attacks in the wild, the presence of an unpatched gateway poses severe operational risks. Tech.yahoo.com points out that a self-hosted AI Gateway acts as a central operational hub, maintaining sensitive JSON Web Token (JWT) signing keys alongside active connections to internal GitLab instances and external AI model providers. A successful exploit grants an attacker direct control over these integrated workflows and authentication credentials, leaving immediate software updates as the sole effective remediation since no software workarounds exist.

Frequently Asked Questions About the GitLab AI Gateway Flaw

GitLab Patches Critical Unauthenticated Path Traversal Flaw | CVE-2026-85706
What specific user roles can trigger CVE-2026-90970?
The advisory specifies that a logged-in user with Duo Agent Platform access is required to reach the flaw, though no more granular user roles are explicitly named in GitLab’s documentation.
Can administrators check if their gateway was attacked before patching?
No. GitLab’s official advisory does not provide any diagnostic method or logging mechanism to determine whether a gateway experienced a compromise prior to being updated.
Why are GitLab-hosted instances exempt from manual patching?
GitLab manages and operates AI Gateways for its cloud and dedicated customers directly, allowing the company to apply all necessary security patches internally before public disclosure.
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”