GitLab has released security updates for a critical vulnerability in its self-hosted AI Gateway that could allow command execution on affected gateway servers. The issue, tracked as CVE-2026-90970, has a CVSS score of 9.9 and affects organizations that run their own GitLab AI Gateway for Duo Agent Platform workloads.

This is a focused patching advisory rather than a broad GitLab emergency for every customer. GitLab says its hosted gateways have already been fixed, and customers using GitLab.com, GitLab Dedicated, or self-managed GitLab instances connected to a GitLab-hosted AI Gateway do not need to take action for this specific gateway issue. The urgent audience is administrators operating a self-hosted AI Gateway through Docker or Helm.

What happened

The vulnerability is described as a flaw in the prompt template handling for a custom flow. In practical terms, a logged-in user with access to the Duo Agent Platform could create a specially crafted flow configuration that escapes the intended prompt template sandbox. Under the right conditions, that escape could lead to arbitrary command execution on the AI Gateway host.

That matters because the gateway is not just a passive web component. It sits between a GitLab instance and AI model providers, processes AI-related requests, and may hold sensitive configuration such as JWT signing keys. If an attacker can run commands on the gateway, defenders should treat the server as a high-value asset and consider whether credentials, configuration files, logs, or network access from that host could have been exposed.

GitLab credited the HackerOne researcher invisiblemeerkat for reporting the issue. The public advisory does not state that the flaw has been exploited in the wild. The Hacker News also notes that CISA’s CVE record listed exploitation as “none” on October 2, but that should not be treated as a reason to delay patching a 9.9-rated command execution bug.

Affected and fixed AI Gateway versions

The fixed AI Gateway releases are 19.2.4, 19.3.2, and 19.4.1. According to the published advisory details, affected versions include AI Gateway 18.1.6 and later before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.

Administrators should note that these are AI Gateway versions, not necessarily the same thing as the main GitLab application version shown in the GitLab UI. Self-hosted gateway deployments are commonly installed as a separate Docker image or Helm chart, so checking only the GitLab application package level may miss the vulnerable component.

If your organization uses GitLab Duo features but is unsure whether the gateway is self-hosted or GitLab-hosted, verify the architecture before closing the ticket. The simplest decision point is whether your team deploys and maintains the AI Gateway container or chart in your own environment. If yes, this advisory likely applies.

Recommended response for administrators

Start by identifying every self-hosted AI Gateway deployment across production, staging, development, and isolated AI testing environments. AI services are sometimes deployed by platform, DevOps, or innovation teams outside the normal application inventory, so do not rely only on the central GitLab server list.

Next, update the gateway to one of the fixed versions: 19.2.4, 19.3.2, or 19.4.1. Docker-based deployments should pull and run a fixed image tag, while Helm-based deployments should update the chart image tag and redeploy according to the organization’s change process. Where possible, align the gateway version with GitLab’s documented compatibility guidance for your GitLab minor release.

Because no workaround was listed in the public reporting, patching is the primary mitigation. If immediate upgrading is blocked, reduce exposure while preparing the update: restrict network access to the gateway, limit who has Duo Agent Platform access, review custom flows, and monitor the host for unexpected child processes, shell execution, outbound connections, or changes to gateway configuration.

After patching, confirm the running container or pod is actually using the fixed image. It is common for teams to update a manifest or pull an image but leave an older workload running. Verification should include the live workload, not just the repository or deployment file.

What to review after the update

For a critical command execution flaw, patching closes the known vulnerability but does not answer whether the host was previously misused. GitLab’s advisory does not provide a specific compromise indicator set, so defenders should perform a general investigation around the gateway.

Review authentication and authorization logs for Duo Agent Platform access, especially by users who created or modified custom flows. Look for unusual flow configurations, unexpected activity from service accounts, and access from unfamiliar locations. On the gateway host or Kubernetes workload, review process execution history where available, container logs, image changes, environment variables, mounted secrets, and outbound network activity.

Sensitive values associated with the gateway, including JWT signing keys and credentials used to connect to GitLab or AI providers, should be considered for rotation if there is any evidence of suspicious activity or if the gateway was broadly accessible before the patch. Organizations with mature incident response processes may choose to rotate these secrets proactively because the impacted component can hold credentials that enable further access.

Why this deserves priority

CVE-2026-90970 combines several risk factors: command execution potential, a critical CVSS score, authenticated but product-specific access requirements, and placement in a component that bridges source-code collaboration systems with AI infrastructure. Even if exploitation requires Duo Agent Platform access, many organizations grant AI workflow features to technical users who also have repository visibility and development privileges.

The broader lesson is that AI orchestration components need the same operational rigor as CI/CD runners, build agents, and automation servers. Prompt templates, custom flows, and AI workflow engines can become execution paths when they interact with template engines, tools, credentials, and backend services. Security teams should include these components in patch management, asset inventory, logging, and access reviews.

Source: The Hacker News source