CVE-2026-90970: Critical GitLab AI Gateway Vulnerability

CVE-2026-90970: Critical GitLab AI Gateway Vulnerability


AI infrastructure is quickly becoming part of the enterprise attack surface, and CVE-2026-90970 is a good example of why.

The vulnerability affects GitLab AI Gateway and carries a CVSS score of 9.9 (Critical). It allows an authenticated user with access to the Duo Agent Platform to potentially escape the sandbox used by prompt templates and execute arbitrary commands on the underlying AI Gateway host.

What Happened?

The issue is a template injection and sandbox escape vulnerability in the custom-flow functionality.

A specially crafted flow configuration can break out of the intended template sandbox. If successfully exploited, the attacker can execute commands on the gateway server.

The attack path is essentially:

Authenticated access → Malicious flow → Sandbox escape → Command execution

The attacker does require access to the affected Duo Agent Platform functionality, but no additional user interaction is required once that access is available.

Affected Versions

Affected versions include:

  • 18.1.6–19.2.3
  • 19.3.0–19.3.1
  • 19.4.0

Fixed versions:

  • 19.2.4
  • 19.3.2
  • 19.4.1

The vulnerability primarily matters to organizations running self-hosted AI Gateway deployments.

Is It Being Exploited?

There is currently no confirmed evidence of active exploitation, and CVE-2026-90970 is not currently listed in the CISA KEV catalog.

That said, a 9.9-rated vulnerability leading to command execution shouldn’t sit in the backlog.

What Should Security Teams Do?

If you’re running a self-hosted AI Gateway:

  1. Identify the deployed version.
  2. Upgrade to a fixed release.
  3. Review Duo Agent Platform and custom-flow permissions.
  4. Check gateway and host logs for suspicious flow configurations or unexpected command execution if the vulnerable version was exposed.
  5. Review what credentials, tokens and internal services the gateway could access.

The Bigger Lesson

The interesting part of CVE-2026-90970 is not just the RCE.

It shows how an AI workflow can become an infrastructure attack path.

Prompt templates, agent flows and AI gateways may look like application-level components, but once they can influence server-side execution, they become part of the security boundary.

AI security and traditional infrastructure security are now closely connected.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.